Truth that Matters. Stories that Impact

Truth that Matters. Stories that Impact

Technology

Why Cybersecurity Firms Name Hacking Groups: Google Explains Its New Tracking System

Google has updated the naming convention used by its cybersecurity teams to identify and classify hacking groups worldwide. The new approach replaces the legacy numbered naming model previously used by Mandiant with a structured two-word system designed to provide clearer attribution and streamline threat tracking across the industry.

What Happened

Cybersecurity organizations have assigned codenames to digital threat actors for over a decade. In the past, Mandiant—which was an independent security firm before joining Google—introduced one of the earliest identification structures using designations like APT1 and APT41. However, as the volume of cyber threats expanded over the years, tracking these numerical identifiers became increasingly complex.

Last month, Google integrated the naming practices of Mandiant and its former Threat Analysis Group under the Google Threat Intelligence Group. The revamped convention pairs a memorable, randomly selected first word with a second word whose first letter identifies the threat group’s suspected nation of origin. Under this structure, country designations include Castle for China, Ion for Iran, Neptune for North Korea, and Relic for Russia.

Key Highlights

  • New Classification System: Google now designates hacking groups using a random first name followed by a specific nation-linked keyword (Castle for China, Ion for Iran, Neptune for North Korea, and Relic for Russia).
  • Scale of Operations: According to John Hultquist, chief analyst at Google Threat Intelligence Group, the company currently monitors more than 5,000 activity clusters across multiple nations.
  • State vs. Non-State Actors: Shane Huntley, chief technology officer of Google Threat Intelligence Group, highlighted that tracking state-backed entities is generally more manageable than monitoring cybercriminals or hackers-for-hire because government-sponsored groups maintain more consistent objectives and operations.
  • Divergent Visibility: Security companies continue to maintain individual naming formats because each firm relies on distinct data sources and telemetry, meaning no single company possesses complete visibility across global digital activity.

Why This Matters

Attribution and systematic naming are critical operational tools rather than mere academic categorizations. According to Shane Huntley, understanding who is behind an attack and recognizing their standard operating procedures allows organizations to detect security risks faster, implement targeted defenses, and conduct prompt incident investigations.

Knowing the historical behavior of specific groups—such as North Korea’s Lazarus Group—provides security teams with a clear starting baseline when managing active breaches. Tracking historical behavior helps defenders understand an attacker’s potential motivations, toolsets, and targets.

Furthermore, state-aligned operations differ significantly from criminal enterprises. While state actors generally exhibit steady patterns, criminal groups frequently change membership or splinter, and commercial spyware vendors operate across broad, decentralized client networks, creating varied tracking challenges for security researchers.

What to Watch Next

Security teams and researchers will observe how Google Threat Intelligence Group applies this unified classification across its threat reports and whether the reduction of overlapping internal schemes simplifies identification for external organizations and policymakers responding to major cyber incidents.

Frequently Asked Questions

Why do cybersecurity companies use different names for the same hacking group?

Different firms rely on their own telemetry and datasets to observe digital attacks. Because no individual organization has complete visibility over all global cyber activity, each firm builds models based on its own findings, often leading to separate internal names for threat actors.

How does Google’s new hacker naming convention work?

The system uses two words: the first is an easily recognizable, random term, while the second word begins with a letter corresponding to the actor’s country of origin, such as Castle (China), Ion (Iran), Neptune (North Korea), or Relic (Russia).

Why are state-sponsored hackers considered easier to track than cybercriminals?

State-sponsored actors typically focus on consistent targets and strategic directives over time. In contrast, cybercriminal groups regularly disperse, rebrand, or switch personnel, and commercial hacker-for-hire entities serve numerous diverse clients globally.

Source: TechCrunch, reporting statements from Google Threat Intelligence Group leaders Shane Huntley and John Hultquist.