Google Adopts New Threat Actor Naming System

Google has introduced a new system for naming threat actors, moving away from sequential numbers and disparate identifiers in favor of a cryptonym-based convention. This shift aims to simplify tracking and facilitate comparisons across different organizations.

The new naming scheme uses two-word combinations, with the first word being a unique term that may have been used in public reporting and represents the threat actor itself. If no such term exists, a randomly generated one is used. The second word categorizes each threat actor based on its motivation, attribution, or activity type. For instance, ‘Castle’ will be used as the second word for Chinese groups, while ‘Relic’ will represent Russian threat actors and ‘Comet’ will identify cybercrime gangs.

The transition to this new taxonomy is already underway, with Google having renamed several dozen of the most active threat actors. This process will continue on a rolling basis, with previous names remaining indexed and searchable in the Google Threat Intelligence (GTI) platform. MITRE ATT&CK mappings and other vendor aliases will also be preserved.

Google’s adoption of this new naming convention is part of an effort to address the issue of varying visibility into the threat landscape among different cybersecurity organizations. This limited visibility hinders direct comparisons between threat actors, making it more challenging for experts to track and understand their activities. By introducing a simpler system, Google seeks to streamline operations and facilitate mapping to other naming taxonomies.

The new taxonomy is also expected to improve coordination and communication among security professionals. By using consistent and easily recognizable names, threat hunters and incident responders can better share information and stay informed about emerging threats. As the threat landscape continues to evolve, having a standardized system for tracking and naming threat actors will be essential in staying ahead of malicious activities.

Google’s move is part of a broader effort by major tech companies to standardize threat actor naming conventions. Microsoft and CrowdStrike have led similar initiatives in the past. This trend suggests that industry leaders are recognizing the importance of shared understanding and coordination in combating cyber threats.

For security professionals, this development serves as a reminder of the need for collaboration and information sharing. As the complexity of threat landscapes continues to grow, having standardized naming conventions will become increasingly essential. By adopting this new taxonomy, Google is contributing to a more cohesive and effective approach to tracking and mitigating emerging threats.


Source: SecurityWeek — 2026-07-28