Full Report
So much for Microsoft and CrowdStrike’s plans for consistent names across the industry
Analysis Summary
# Industry News: Google Shatters Dreams of Unified Threat Actor Naming
## Summary
Google has announced a proprietary taxonomy for naming cyber threat actors, effectively ending hopes for a unified industry naming convention previously spearheaded by Microsoft and CrowdStrike. By introducing its own two-word schema (e.g., "RELIC" for Russia, "CASTLE" for China), Google is prioritizing its internal integration following the Mandiant acquisition over broader industry standardization.
## Key Details
- **Date:** July 25, 2026 (Announced)
- **Companies Involved:** Google (Google Threat Intelligence Group), Microsoft, CrowdStrike, Mandiant.
- **Category:** Taxonomy Update / Strategic Industry Shift.
## The Story
In 2025, a movement led by Microsoft and CrowdStrike sought to solve one of the most frustrating problems in cybersecurity: "name fatigue." Currently, a single Russian state-sponsored group can have over a dozen aliases (such as APT44, Seashell Blizzard, or VOODOO BEAR), making cross-vendor intelligence sharing a manual nightmare for defenders.
While sources previously indicated Google and its subsidiary Mandiant were on board with a unified scheme, Google has now pivoted. Following the merger of Mandiant and Google’s internal security teams into the Google Threat Intelligence Group (GTIG), the search giant unveiled a new two-word naming convention. The system assigns a unique, randomly generated first word followed by a second word representing the origin or motive (e.g., ION for Iran, NEPTUNE for North Korea). Google claims this "randomized" approach removes geopolitical bias, which has been a point of contention with nations like China.
## Business Impact
### For the Companies Involved
- **Google:** Consolidates its brand identity post-Mandiant acquisition. By owning its naming convention, Google reinforces its position as a primary source of truth in threat intelligence.
- **Microsoft & CrowdStrike:** Their push for an industry standard is significantly weakened. Without the participation of a major intelligence collector like Google/Mandiant, a "universal" standard remains out of reach.
### For Competitors
- Other vendors must now decide whether to map their intelligence to Google’s new system or stick to their own, further fragmenting the "Rosetta Stone" of threat intelligence.
### For Customers
- **Increased Complexity:** Security operations center (SOC) analysts will continue to spend billable hours mapping disparate names across tools (e.g., a "Relic" alert in Google Chronicle vs. a "Blizzard" alert in Microsoft Sentinel).
### For the Market
- This move signals that "brand differentiation" in threat intelligence currently outweighs "industry collaboration." Intelligence is being treated as a proprietary product rather than a communal utility.
## Technical Implications
The new schema utilizes a two-word system:
1. **Unique Descriptor:** A memorable, often randomly generated term to identify the specific actor.
2. **Motivation/Origin Tag:**
- **CASTLE:** China
- **ION:** Iran
- **NEPTUNE:** North Korea
- **RELIC:** Russia
- **COMET:** Non-state affiliated/Cybercrime
## Strategic Analysis
- **Market Positioning:** Google is positioning itself as the "objective" intelligence provider. By using random names to "remove bias," they appeal to global markets that may view Western-centric naming (like "Panda" or "Typhoon") as politically charged.
- **Competitive Advantage:** Google can now leverage the deep "Mandiant legacy" under a unified Google-branded umbrella, forcing those who want Mandiant-level data to adopt Google’s language.
- **Challenges:** Interoperability remains the biggest hurdle. If the industry does not follow suit, Google’s names will just be another layer of noise in an already crowded data field.
## Industry Reactions
- **Analyst Opinions:** Many analysts see this as a setback for "collective defense," noting that fragmentation only benefits the attackers by slowing down the defenders' response time.
- **Market Response:** Disappointment from the "Open Source Intelligence" (OSINT) community, which has long advocated for a single, CVE-like identifier for threat actors.
## Future Outlook
- **Predictions:** We are unlikely to see a unified naming convention this decade. Instead, expecting the rise of "translation middleware"—automated tools specifically designed to map threat names across different vendor platforms.
- **What to Watch for:** Watch whether other major players like Palo Alto Networks (Unit 42) or Cisco (Talos) adopt Google’s "randomized" approach or continue their own unique paths.
## For Security Professionals
Practitioners should expect continued "name sprawl." It is recommended to prioritize the use of **MITRE ATT&CK IDs** or **Internal Tracking Numbers** rather than vendor-specific names to maintain consistency in internal reporting and incident response playbooks.