Google Changes How It Names Cyber Threat Actors: What Security Pros Need to Know

Google is moving to two-word cryptonyms for cyber threat actors, aiming for clarity—but security teams may face more complexity, not less.

Google Changes How It Names Cyber Threat Actors: What Security Pros Need to Know
Andrew Wallace

Andrew Wallace

Professional Tech Editor

Focuses on professional-grade hardware, software, and enterprise solutions.

What is Google’s new threat actor naming system?

Google’s Threat Intelligence Group has introduced a new naming system for cyber threat actors it tracks, using distinctive two-word cryptonyms. The new scheme replaces previous identifier patterns, such as numbers or legacy names inherited from various acquisitions. In the new approach, the first word is either a familiar nickname (if the group already has industry recognition) or a randomly assigned term. The second word signals attribution or motive: for example, "CASTLE" denotes activity linked to China, "ION" to Iran, "NEPTUNE" to North Korea, "RELIC" to Russia, and "COMET" to financially motivated cybercriminals.

How does this affect security teams and defenders?

Google Breaks Up NetNut Residential Proxy Network
Google Breaks Up NetNut Residential Proxy Network

The intention is to create a more intuitive and meaningful system. Numbers such as APT28 or descriptive labels can be opaque and offer little context for first responders or analysts. Google's update is designed to let defenders more quickly identify attribution and attacker motivation. However, the reality for most security teams is likely to be more complex, not less. Despite efforts at streamlining, there’s now yet another naming scheme to learn alongside those from Microsoft, CrowdStrike, and other major security vendors. This risks adding confusion in environments already crowded with aliases and mapping tables.

What are the practical trade-offs and industry implications?

While Google’s cryptonym system borrows from similar approaches (such as CrowdStrike’s use of animal-based tags), it diverges by adopting its own unique conventions. This move comes shortly after major industry players began collaborating to map different naming schemas, aiming at standardization. With Google adopting a parallel path, organizations will have to contend with another dimension of threat actor labeling, potentially complicating incident response, threat intelligence sharing, and cross-vendor analysis. For security buyers and analysts, it’s important to understand both the intention—quicker, clearer context—and the ongoing need to map and reconcile multiple schemes in daily operations.

Should security professionals adopt Google’s naming or stick to industry standards?

Google Threat Intelligence for ITSM - ServiceNow Store
Google Threat Intelligence for ITSM - ServiceNow Store

For most organizations, operational efficiency is best served by maintaining a reference table that maps Google’s new cryptonyms to more widely used names and standards. If your team relies primarily on Google’s threat intelligence platforms, adopting the new terms may make sense. However, if you work in multi-vendor environments or participate in information sharing communities, the priority should be on clarity and interoperability—which means staying familiar with all major naming conventions in parallel.

Key takeaway: Prepare for more naming complexity, not less

While the intention behind Google's new naming convention is to simplify and clarify threat actor attribution, in practice, security teams will need to be ready for additional complexity. Effective coordination across the industry remains a work in progress. Track changes closely, and consider tools or processes that help map and translate between different schemes to avoid missed connections or confusion during active incident response.

React to this story

Related Posts