Tech

Google overhauls cyber threat naming convention to track 5,000 global activity clusters

Google Threat Intelligence Group chief technology officer Shane Huntley says the shift from numerical identifiers to memorable codenames is essential as the number of state-sponsored and criminal hacking groups expands.

Author
Owen Mercer
Markets and Finance Editor
Published
Draft
Source: TechCrunch · original
Google’s top hacker hunter explains why hacking groups get codenames
New system replaces legacy APT codes with country-specific suffixes to improve clarity for security researchers

Google has formally retired its legacy Advanced Persistent Threat (APT) numbering scheme, introducing a new naming convention for cyber threat groups that pairs a memorable first name with a second word indicating the country of origin. The update, adopted by the Google Threat Intelligence Group, aims to streamline identification for security researchers and assist organisations in responding more effectively to emerging threats.

Under the revised system, specific suffixes denote the nation behind the activity. Castle is assigned to groups linked to China, Ion to Iran, Neptune to North Korea, and Relic to Russia. This structure replaces the numerical identifiers such as APT1 or APT41, which were previously popularised by Mandiant, a security firm now integrated into Google’s operations.

Shane Huntley, chief technology officer of the Google Threat Intelligence Group, stated that the change was driven by the sheer volume of modern cyber threats. In the early 2010s, when the industry first began publishing reports on cyberattacks and assigning names to the hackers involved, the number of distinct groups was significantly lower. Today, the landscape has shifted dramatically, with Huntley noting that very few developed nations operate without their own cyber capabilities.

Google currently monitors more than 5,000 activity clusters globally, according to John Hultquist, chief analyst at the Google Threat Intelligence Group. Huntley explained that while state-sponsored hackers are generally easier to track due to consistent targets and activities, cybercriminal groups and hackers-for-hire present greater challenges. These non-state actors often feature fluid membership, splintering factions, and diverse customer bases across different regions.

The primary objective of the new naming protocol is to establish a baseline understanding of threat actor behaviour. By consistently tracking how specific groups operate, organisations can recognise threats more quickly, prepare defences, and investigate incidents with greater precision. Huntley emphasised that knowing an actor’s history and objectives is critical for effective incident response and coverage planning.

Huntley also addressed the longstanding industry debate regarding the lack of a universal naming standard. He noted that every security company maintains a slightly different view of threat groups based on its unique data and telemetry. Because no single entity possesses perfect visibility, a unified global standard is difficult to enforce, though unifying Google’s former Threat Analysis Group and Mandiant schemes reduces the number of internal identifiers staff must remember.

Continue reading

More from Tech

Read next: France Enacts Strict Ban on Unsolicited Telemarketing Calls
Read next: OpenAI expands Daybreak cybersecurity programme with new model tiers
Read next: AI models map 766 genes in schizophrenia genetic architecture