Google has revamped its naming system for hacking groups, replacing the old APT numbering scheme inherited from Mandiant with a new format: a memorable first name plus a second word whose initial indicates country of origin (Castle for China, Ion for Iran, Neptune for North Korea, Relic for Russia). Shane Huntley, CTO of Google Threat Intelligence Group, explains that consistent naming is essential for defenders to recognize threats, prepare responses, and investigate incidents. Google now tracks over 5,000 activity clusters globally. The fragmentation of naming across companies persists because each organization has different data and telemetry, making a single universal standard impractical.
Questions this post answers
What is Google's new naming system for hacking groups and what do the second-word initials mean?
Google's new system gives each hacking group a memorable random first name and a second word whose initial indicates country of origin: Castle for China, Ion for Iran, Neptune for North Korea, and Relic for Russia. This replaces the old APT numbering scheme inherited from Mandiant, which had become difficult to track as Google now monitors more than 5,000 activity clusters globally. Threat intelligence teams keeping pace with actor taxonomy changes follow developments like these on daily.dev.
Why do cybersecurity companies use different codenames for the same hacking groups instead of a universal standard?
Each company has a slightly different view of every hacking group based on its own data and telemetry, making a single universal naming standard impractical. Even with more information sharing, no organization has perfect visibility into all threat actor activity, so each builds its own model. Resources like the MITRE ATT&CK groups list exist to help map between different naming schemes. Security researchers reconciling actor names across vendors track these taxonomy discussions on daily.dev.