Full Report
APT-number conventions are out, cryptonyms are in, and security teams now have one more naming system to keep straight. The post Google’s solution to hacker name confusion? Yet another naming system appeared first on CyberScoop.
Analysis Summary
# Industry News: Google Unifies Threat Actor Taxonomy with New Naming System
## Summary
Google Threat Intelligence has officially transitioned to a new two-word naming convention for threat actors, moving away from numeric APT designations. This move unifies the separate naming systems previously used by Mandiant and Google’s Threat Analysis Group (TAG) into a single, intuitive framework.
## Key Details
- **Date:** July 2026 (Reported)
- **Companies Involved:** Google (Mandiant, Threat Analysis Group), Microsoft, CrowdStrike
- **Category:** Product Update / Operational Realignment
## The Story
Following the 2022 acquisition of Mandiant, Google faced an internal challenge: two distinct teams tracking the same hackers under different names. To resolve this, Google has introduced a "cryptonym" system that pairs a memorable first word with a second word indicating the actor's origin or motivation.
The taxonomy uses specific suffixes to categorize threats:
- **CASTLE:** China
- **NEPTUNE:** North Korea
- **ION:** Iran
- **RELIC:** Russia
- **COMET:** Financially motivated (non-state)
This shift mirrors similar moves by CrowdStrike (Animals) and Microsoft (Weather). To mitigate industry-wide confusion caused by this "naming sprawl," Google has also joined a joint mapping effort with Microsoft and CrowdStrike to ensure that different vendor names can be cross-referenced effectively.
## Business Impact
### For the Companies Involved
- **Google:** Streamlines internal operations by merging Mandiant and TAG intelligence feeds, reducing redundant work and branding friction.
- **Mandiant:** Effectively retires the iconic "APT[Number]" branding in favor of the new Google-integrated system.
### For Competitors
- **CrowdStrike & Microsoft:** The adoption of a similar "word-pair" system by Google validates their existing taxonomies but also increases the "cognitive load" on shared customers who must now track a third major naming convention.
### For Customers
- **Information Overload:** CISOs and security teams must now map "Sandworm Relic" to "Seashell Blizzard" (Microsoft) and "Voodoo Bear" (CrowdStrike), potentially slowing down incident response due to terminology confusion.
### For the Market
- **Standardization Efforts:** The news highlights the failure of the industry to adopt a single universal naming standard, leading back to "Rosetta Stone" style mapping projects rather than a unified language.
## Technical Implications
The system incorporates "UNC" (Uncategorized) designations for emerging threats, allowing for flexibility before a permanent name is assigned. Google is also integrating these names with the **MITRE ATT&CK** framework, ensuring that the names serve as a gateway to technical behavioral data rather than just being catchy labels.
## Strategic Analysis
- **Market Positioning:** Google is positioning itself as an intuitive, intelligence-led leader, moving away from "dry" numeric systems to more brandable, memorable identities.
- **Competitive Advantage:** By leading the mapping initiative with Microsoft and CrowdStrike, Google ensures its intelligence remains a central pillar of the global security ecosystem.
- **Challenges:** The primary risk is "Naming Fatigue"—the possibility that the industry ignores new names and continues to use older, more established identifiers out of habit.
## Industry Reactions
- **Analyst Opinions:** General acknowledgment that numeric systems (APT28, etc.) were becoming difficult to manage as the number of tracked groups exploded.
- **Expert Commentary:** Some skepticism remains regarding the "whimsical" nature of modern names (e.g., "Strawberry Tempest"), with some experts arguing they detract from the seriousness of the threats.
## Future Outlook
- Expect a gradual phase-out of numeric "APT" labels across the broader industry.
- Watch for the success of the Microsoft-CrowdStrike-Google "joint mapping effort" to see if it actually reduces complexity or simply adds another layer of administrative overhead.
## For Security Professionals
Practitioners should update their internal documentation to include these new Google aliases. Focus should remain on the **MITRE ATT&CK TTPs** (Tactics, Techniques, and Procedures) rather than the names themselves, as the underlying behavior remains the constant across all naming conventions.