Google Unveils Unified Naming System for Tracking Cyber Threat Actors

Google Threat Intelligence Group (GTIG) announced a major overhaul to how it tracks and names cyber threat actors, rolling out a unified cryptonym-based naming schema designed to standardize threat attribution across platforms.

The change addresses long-standing fragmentation between Mandiant and Google’s Threat Analysis Group (TAG), which historically operated separate, independently evolved tracking systems.

The merger that created GTIG exposed a structural problem: two parallel naming conventions meant defenders often had to reconcile duplicate or conflicting identifiers for the same threat actor.

Google Unveils Unified Naming System

Legacy naming approaches, including sequential numbering schemes like “APT1,” lack the contextual richness security teams need for rapid decision-making.

The Russian state-linked group long tracked as APT44, also known publicly as Sandworm, illustrates the problem: it has accumulated aliases including Dark Basin, Frozenbarents, Greyenergy, Hades, Inedibleochotense, and Quedagh over its operational history dating back to 2004

According to GTIG, effective threat tracking should function as an intuitive reference system rather than a memorization exercise, prompting the shift toward a more industry-aligned cryptonym model.

The updated system assigns each threat actor a memorable two-word cryptonym. The first word serves as a unique identifier, often drawn from prior public reporting where such names already exist.

When no established term is available, GTIG generates a randomized word, then validates it through analyst review to minimize bias.

The second word functions as a category label indicating motivation, attribution, or activity type, chosen based on what GTIG considers most operationally relevant for defenders.

Threat actor name appearance in GTI platform on initial rollout (Source: Google)
Threat actor name appearance in GTI platform on initial rollout (Source: Google)

Under this system, APT44/Sandworm has been reclassified as “SANDWORM RELIC,” with RELIC signaling Russian state attribution.

Origin or TypeGroup Name
People’s Republic of ChinaCASTLE
IranION
North KoreaNEPTUNE
RussiaRELIC
CybercriminalCOMET

This structure lets analysts infer attribution context directly from the name itself, streamlining triage and cross-team communication.

GTIG notes that the schema should remain simple enough to map cleanly onto other vendors’ naming taxonomies, acknowledging the crowded landscape of threat actor tracking systems.

However, the group flagged an important caveat: since no two organizations share identical visibility into the threat landscape, direct comparisons between naming schemas across vendors remain inherently imprecise.

The simplified convention is framed as a practical improvement rather than a definitive solution to the broader attribution challenge. GTIG is prioritizing renaming for several dozen of the most active threat groups first, with additional actors to follow on a rolling basis.

Legacy names won’t disappear; previous identifiers will stay indexed and searchable within the Google Threat Intelligence (GTI) platform, alongside preserved MITRE ATT&CK framework mappings and aliases used by other vendors. This preserves backward compatibility for analysts and researchers who reference historical reporting.

For security teams and threat intelligence practitioners, the transition introduces a learning curve as new cryptonyms replace familiar identifiers across dashboards, alerts, and reports.

Organizations relying on GTI for threat feeds should monitor the rollout closely and update internal documentation, playbooks, and detection rules to reflect the new naming conventions as they propagate through the platform.

Cut SOC investigation blind spots and contain threats earlier to reduce response costs and business disruption with ANY.RUN. 

Tamilselvan
Tamilselvanhttps://cyberpress.org/
Tamilselvan is an Investigative cybersecurity journalist dedicated to breaking stories on ransomware cartels, data breaches, and state-sponsored espionage.

Trending News

Related Stories