Close Menu
    Facebook X (Twitter) Instagram
    Wednesday, August 19
    • Home
    • About Us
    • Contact Us
    • Submit Your Story
    • Terms of Use
    • Privacy Policy
    Facebook X (Twitter) Instagram
    Fortune Herald
    • Business
    • Finance
    • Politics
    • Lifestyle
    • Technology
    • Property
    • Business Guides
      • Guide To Writing a Business Plan UK
      • Guide to Writing a Marketing Campaign Plan
      • Guide to PR Tips for Small Business
      • Guide to Networking Ideas for Small Business
      • Guide to Bounce Rate Google Analyitics
    Fortune Herald
    Home»Business»Google Hacker Naming System Gets Its Biggest Overhaul Yet
    Google hacker naming system
    Business

    Google Hacker Naming System Gets Its Biggest Overhaul Yet

    Funke AdeyemiBy Funke Adeyemi19/08/2026No Comments5 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    The Google hacker naming system has just been rebuilt from scratch, replacing a patchwork of numerical codes and competing internal schemes with a single, two-word cryptonym structure designed to survive the scale of modern cyber-threat tracking.

    The change, announced by Google Threat Intelligence Group (GTIG), retires designations such as APT1, APT41, and every other APT-plus-number variant that Mandiant, now part of Google, had used since it pioneered the practice of publicly naming state-backed hacking groups. Under the new scheme, each group receives a first word, either a retained public alias or a randomly generated name chosen to avoid analyst bias, and a second word whose opening letter signals the country of origin: Castle for China, Ion for Iran, Neptune for North Korea, Relic for Russia.

    Why the Google Hacker Naming System Had to Change

    The pressure to overhaul had been building inside Google since its $5.4 billion acquisition of Mandiant in 2022. That deal left the company with two internal teams, GTIG’s predecessor Threat Analysis Group (TAG) and Mandiant, each running parallel tracking systems that had diverged over years, according to CyberScoop. The same hacking group could carry different names depending on which team’s report a researcher happened to read.

    Shane Huntley, a cofounder of TAG and now chief technology officer of GTIG, has spent 14 years building the infrastructure to detect and disrupt government-backed threats. He told journalists that when companies began publishing threat reports in the early 2010s, nobody anticipated the volume of groups that would need tracking. Google now monitors more than 5,000 ‘activity clusters’ across dozens of countries.

    ‘We were not expecting to have as many threat groups as we do today,’ Huntley said.

    The practical consequences show up in the mapping table published on Google’s official blog. Russia’s Sandworm, previously catalogued internally as APT44, becomes Sandworm Relic. Iranian groups get reorganised under the Ion suffix: APT33 becomes BLEAK ION, APT34 becomes SOLAR ION, APT35 becomes RICH ION. North Korea’s APT37 becomes PLAIN NEPTUNE. Several financially motivated groups that had carried FIN designations, such as FIN7 and FIN11, are now WILD COMET and RAZOR COMET respectively, using Comet as the suffix for criminal clusters.

    Where a group already carries a well-known public name, that name is kept as the first word. Where no suitable public name exists, analysts review randomly generated candidates rather than choosing one themselves, a deliberate step to reduce individual bias in labelling. Groups not yet categorised continue to carry the ‘UNC’ (uncategorised) prefix, and the initial rollout covers several dozen of the most actively tracked groups, with more to follow on a rolling basis.

    Russia’s Sandworm illustrates just how cluttered the industry-wide namespace has become. SecurityWeek notes that the same group is tracked across the wider cybersecurity community under at least 14 separate aliases, including Blue Echidna, Voodoo Bear, Seashell Blizzard, TeleBots, and Iron Viking, depending on which vendor’s intelligence platform a defender is using.

    The Problem No Naming System Can Fully Solve

    Naming is not a cosmetic exercise. Huntley’s argument is operational: when an organisation discovers it has been compromised, knowing which group is responsible tells defenders what tools that actor favours, what infrastructure they typically reuse, and what their past targets suggest about their objectives.

    ‘If you actually get hacked by them or you’re dealing with some incident, knowing how that actor behaves, what they do, what they’ve done in the past, all of these details become critically important to help the response and also work out your coverage against these threats as well,’ Huntley said.

    The Lazarus Group, North Korea’s most prominent hacking arm, is a standard example: defenders who know Lazarus’s history of financial theft and infrastructure attacks enter an incident with a usable hypothesis, rather than starting from nothing.

    Yet even a unified Google hacker naming system cannot resolve the industry’s deepest structural problem: every vendor sees a different slice of global traffic. Huntley was direct about that limit. ‘No one has perfect visibility,’ he said. ‘We are building our model and our best understanding, but we will never know everything about what’s going on.’

    A cross-industry effort is underway to ease the confusion without mandating a single universal label. Microsoft and CrowdStrike have announced a joint mapping project that pairs Microsoft’s weather-based names with CrowdStrike’s animal-based names for the same tracked groups, with Google among those signed on to contribute, according to The Tech Buzz. Both companies have been explicit that the project is not an attempt to impose a single standard. The goal is translation, not consolidation.

    For Huntley and GTIG, the immediate win is narrower but real: the two internal schemes that diverged after the Mandiant acquisition are now one. Whether the rest of the industry eventually converges, or continues to maintain its own parallel taxonomies, will depend less on nomenclature than on whether vendors can agree on what they are actually looking at.

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Funke Adeyemi

    Funke Adeyemi spent a decade in corporate banking and fintech before moving to business journalism. She started in trade finance at a major UK bank, moved to a payments company scaling into African markets, and spent her last role leading partnerships at a cross-border remittance platform. She writes about business strategy, fintech, digital banking, and the corporate news that moves markets. She is interested in how companies actually make money rather than how they describe making money in investor presentations. Funke lives in South London. She reads earnings calls the way other people listen to podcasts, and finds them about as reliable.

    Related Posts

    OpenAI Astra Critical Cybersecurity Threshold Triggers New Safeguards

    18/08/2026

    Cloudflare Kitesurf Browser Cuts AI Agent CPU Load by Up to 7×

    18/08/2026

    Trump Offshore Wind Cancellations Reach $3.93bn After RWE’s $1.22bn Exit

    18/08/2026
    Leave A Reply Cancel Reply

    Fortune Herald Logo

    Connect with us

    FortuneHerald Logo

    Home   About Us   Contact Us   Submit Your Story   Terms of Use   Privacy Policy

    Type above and press Enter to search. Press Esc to cancel.