The Google hacker naming system has just been rebuilt from scratch, replacing a patchwork of numerical codes and competing internal schemes with a single, two-word cryptonym structure designed to survive the scale of modern cyber-threat tracking.
The change, announced by Google Threat Intelligence Group (GTIG), retires designations such as APT1, APT41, and every other APT-plus-number variant that Mandiant, now part of Google, had used since it pioneered the practice of publicly naming state-backed hacking groups. Under the new scheme, each group receives a first word, either a retained public alias or a randomly generated name chosen to avoid analyst bias, and a second word whose opening letter signals the country of origin: Castle for China, Ion for Iran, Neptune for North Korea, Relic for Russia.
Why the Google Hacker Naming System Had to Change
The pressure to overhaul had been building inside Google since its $5.4 billion acquisition of Mandiant in 2022. That deal left the company with two internal teams, GTIG’s predecessor Threat Analysis Group (TAG) and Mandiant, each running parallel tracking systems that had diverged over years, according to CyberScoop. The same hacking group could carry different names depending on which team’s report a researcher happened to read.
Shane Huntley, a cofounder of TAG and now chief technology officer of GTIG, has spent 14 years building the infrastructure to detect and disrupt government-backed threats. He told journalists that when companies began publishing threat reports in the early 2010s, nobody anticipated the volume of groups that would need tracking. Google now monitors more than 5,000 ‘activity clusters’ across dozens of countries.
‘We were not expecting to have as many threat groups as we do today,’ Huntley said.
The practical consequences show up in the mapping table published on Google’s official blog. Russia’s Sandworm, previously catalogued internally as APT44, becomes Sandworm Relic. Iranian groups get reorganised under the Ion suffix: APT33 becomes BLEAK ION, APT34 becomes SOLAR ION, APT35 becomes RICH ION. North Korea’s APT37 becomes PLAIN NEPTUNE. Several financially motivated groups that had carried FIN designations, such as FIN7 and FIN11, are now WILD COMET and RAZOR COMET respectively, using Comet as the suffix for criminal clusters.
Where a group already carries a well-known public name, that name is kept as the first word. Where no suitable public name exists, analysts review randomly generated candidates rather than choosing one themselves, a deliberate step to reduce individual bias in labelling. Groups not yet categorised continue to carry the ‘UNC’ (uncategorised) prefix, and the initial rollout covers several dozen of the most actively tracked groups, with more to follow on a rolling basis.
Russia’s Sandworm illustrates just how cluttered the industry-wide namespace has become. SecurityWeek notes that the same group is tracked across the wider cybersecurity community under at least 14 separate aliases, including Blue Echidna, Voodoo Bear, Seashell Blizzard, TeleBots, and Iron Viking, depending on which vendor’s intelligence platform a defender is using.
The Problem No Naming System Can Fully Solve
Naming is not a cosmetic exercise. Huntley’s argument is operational: when an organisation discovers it has been compromised, knowing which group is responsible tells defenders what tools that actor favours, what infrastructure they typically reuse, and what their past targets suggest about their objectives.
‘If you actually get hacked by them or you’re dealing with some incident, knowing how that actor behaves, what they do, what they’ve done in the past, all of these details become critically important to help the response and also work out your coverage against these threats as well,’ Huntley said.
The Lazarus Group, North Korea’s most prominent hacking arm, is a standard example: defenders who know Lazarus’s history of financial theft and infrastructure attacks enter an incident with a usable hypothesis, rather than starting from nothing.
Yet even a unified Google hacker naming system cannot resolve the industry’s deepest structural problem: every vendor sees a different slice of global traffic. Huntley was direct about that limit. ‘No one has perfect visibility,’ he said. ‘We are building our model and our best understanding, but we will never know everything about what’s going on.’
A cross-industry effort is underway to ease the confusion without mandating a single universal label. Microsoft and CrowdStrike have announced a joint mapping project that pairs Microsoft’s weather-based names with CrowdStrike’s animal-based names for the same tracked groups, with Google among those signed on to contribute, according to The Tech Buzz. Both companies have been explicit that the project is not an attempt to impose a single standard. The goal is translation, not consolidation.
For Huntley and GTIG, the immediate win is narrower but real: the two internal schemes that diverged after the Mandiant acquisition are now one. Whether the rest of the industry eventually converges, or continues to maintain its own parallel taxonomies, will depend less on nomenclature than on whether vendors can agree on what they are actually looking at.
