Skip to content
Malware

Google Is Giving Hacker Groups New Names That Reveal Who They Are and Why They Attack

Google is changing how it names the hacker groups it tracks, replacing a patchwork of labels with names designed to explain more at a glance. The change is intended to make threat reports easier to follow when defenders are trying to understand who is behind an operation and what may drive it. The r...

· Jul 27, 2026 · 4 min read · 👁 0 views
Google Is Giving Hacker Groups New Names That Reveal Who They Are and Why They Attack

Google is changing how it names the hacker groups it tracks, replacing a patchwork of labels with names designed to explain more at a glance.

The change is intended to make threat reports easier to follow when defenders are trying to understand who is behind an operation and what may drive it.

The rollout does not describe a new malware strain or a single attack campaign. Instead, it addresses a long-standing problem in threat intelligence: different research teams can use different names for the same cluster, while a short label may reveal little about its origin, motives, or activity.

Analysts at Google Cloud noted that the unified scheme is being rolled out by the Google Threat Intelligence Group, following the combination of Mandiant and Google’s Threat Analysis Group.

The aim is to standardize tracking across platforms and public reporting, reducing the memorization burden placed on security teams.

Google Cloud said in a report shared with Cyber Security News (CSN) that for organizations, clearer labels can speed up triage, improve communication between analysts, and make external reporting less confusing.

It will not replace careful attribution work, however, because attacker behavior, infrastructure, and targets still need to be assessed before a group is linked to a government or criminal operation.

Google Is Giving Hacker Groups New Names

Under the new model, each actor receives a memorable two-word cryptonym. The first word identifies the specific group and may retain a term used in earlier public reporting; if no established term exists, researchers generate one randomly and review it to avoid bias.

The second word supplies the useful context. CASTLE denotes groups linked to the People’s Republic of China, ION is used for Iran, NEPTUNE for North Korea, RELIC for Russia, and COMET for cybercriminal activity.

That approach gives readers a quick starting point without claiming that every case has the same level of certainty.

The sequential numbers and disconnected identifiers such as APT1 do not provide the context defenders need to act quickly.

Threat actor name appearance in GTI platform on initial rollout (Source - Google Cloud)
Threat actor name appearance in GTI platform on initial rollout (Source – Google Cloud)

Readers comparing labels can also consult new attribution framework connects APT campaigns, which explains why strong conclusions should rest on several independent forms of evidence.

Previous labels are not disappearing overnight. Google says earlier names will remain searchable in its threat intelligence platform, alongside MITRE ATT&CK mappings and aliases from other vendors.

This continuity matters when incident teams must reconcile older reports, monitoring rules, and case notes with new assessments.

Tracking During Transition

The transition will begin with several dozen of the most active groups and continue over time. Groups still at an early stage of investigation will continue to carry UNC, meaning uncategorized, labels.

That restraint is important: a familiar name can be helpful, but it should not make a tentative assessment appear settled.

Security teams should treat the new names as a navigation aid, not a shortcut for attribution. Cross-check the actor label against the campaign’s tools, victim profile, timing, and infrastructure, and preserve older aliases in searches during the transition.

Guidance in this hands on threat hunting guide offers a useful reminder that MITRE ATT&CK techniques can organize an investigation without proving who conducted it.

Teams should also document why a mapping was made and the confidence behind it, particularly when public reporting uses several overlapping names.

A practical advanced threat tracking guide can help analysts keep campaign evidence separate from the label, reducing the chance that an old alias hides a fresh pattern of activity.

The broader benefit is a common language that is easier to remember while leaving room for uncertainty and new evidence. It may also make it easier for non-specialists to follow reports about state-backed and financially motivated activity.

For context on the latter risk, coverage of cybercriminal attacks targeting users shows why clear threat communication matters when the people behind an intrusion can change their tools and tactics quickly.

Clear terminology cannot prevent an intrusion, but it can help organizations exchange findings faster and decide what requires attention first.

Source: CybersecurityNews.com

Follow ShomoySoft for more: Follow on Facebook

💬 Comments (0)

Login to join the discussion.

No comments yet. Be the first!

Related Articles

Recommended for you