Google’s hacker naming system has been redesigned from scratch, replacing a decade of unwieldy alphanumeric codes with two-word cryptonyms whose second word signals a group’s country of origin. Castle for China, Ion for Iran, Neptune for North Korea, Relic for Russia.
The overhaul comes from Google Threat Intelligence Group (GTIG), which merged the former Threat Analysis Group with Mandiant after Google’s acquisition of the security firm. The old system inherited from Mandiant, APT1 through to APT-whatever-comes-next, was the first naming scheme the industry ever adopted, originating with Mandiant’s landmark February 2013 report exposing APT1 as a Chinese military cyber-espionage unit. It made sense at the time. Then came 5,000 tracked clusters and counting.
Why the Google Hacker Naming System Needed a Reset
‘We were not expecting to have as many threat groups as we do today,’ Shane Huntley, GTIG’s chief technology officer, said. Google now tracks more than 5,000 ‘activity clusters’ across several countries, according to John Hultquist, GTIG’s chief analyst. Huntley said there are very few developed nations without their own cyber capabilities.
The practical problem is memory and recognition. If a defender sees malware that matches a known group’s patterns, they need to call that group something consistent to act on the knowledge quickly. ‘If you actually get hacked by them or you’re dealing with some incident, knowing how that actor behaves, what they do, what they’ve done in the past, all of these details become critically important to help the response and also work out your coverage against these threats as well,’ Huntley said.
The new scheme gives each group a memorable first word, chosen to avoid bias. According to Gigazine, when no established public name already exists for a group, GTIG analysts review randomly generated name candidates rather than picking one themselves. The second word does the geographic work. Previous names remain indexed and searchable in the GTI platform, with MITRE ATT&CK mappings and other vendor aliases preserved alongside the new cryptonyms.
The rollout began with ‘several dozen’ of the most active groups, with renaming continuing on a rolling basis. Some of the mappings illustrate how clean the new scheme actually is: APT41 becomes SPIRE CASTLE, APT40 becomes ISLAND CASTLE, APT27 becomes SHORE CASTLE, APT31 becomes TIDE CASTLE, and APT5 becomes BASALT CASTLE. On the Iran side, APT42 (previously also known as CALANQUE) becomes CALANQUE ION. North Korean groups APT37 and APT45 become PLAIN NEPTUNE and GRASS NEPTUNE respectively. Financial crime groups FIN7 and FIN11 become WILD COMET and RAZOR COMET.
Why One Shared Naming System Remains a Pipe Dream
The Sandworm case illustrates how messy the current landscape is. Russia’s Sandworm group, previously tracked by GTIG as APT44, becomes SANDWORM RELIC under the new system. Across the broader security community, the same group carries at least 13 other aliases, including Seashell Blizzard, TeleBots, Voodoo Bear, Iron Viking, and Electrum, depending on which vendor’s report you’re reading.
Every company produces its own names because every company has its own data and telemetry. Proofpoint uses numbered TA groups, Symantec uses insect species, Microsoft uses chemical elements, Recorded Future uses colour-plus-phonetic combinations, and Secureworks pairs elements with nicknames. None of them are wrong, exactly. They just see different parts of the same activity.
Huntley was direct about whether greater information-sharing could fix the fragmentation. ‘No one has perfect visibility,’ he said. ‘We are building our model and our best understanding, but we will never know everything about what’s going on.’
Tracking state-sponsored groups is at least relatively tractable: government hackers tend to have consistent targets and consistent methods. Cybercriminal groups are harder. Members come and go, factions split off, and the organisations reshape themselves. Hackers-for-hire and commercial spyware vendors add another layer of complexity, serving customers across multiple countries and jurisdictions.
GTIG will continue using its ‘UNC’ designation for clusters that haven’t yet been characterised fully enough to earn a name. So the taxonomy has a staging area, which is a sensible bit of epistemic humility for an industry that, by its own admission, will never have the complete picture.
By consolidating Mandiant’s scheme with the former Threat Analysis Group’s scheme, Google has at least eliminated one set of competing labels. The broader alphabet-soup problem endures. The next time a major breach surfaces and three vendors publish three different names for the same group on the same day, at least the decoder ring for Google’s entries will be a little more intuitive.
