Full Report
Introduction Today, Google Threat Intelligence Group (GTIG) will begin rolling out a unified naming schema for tracking threat actors. This new naming taxonomy represents an effort to standardize tracking across platforms and public reporting. Why are we Adopting a Different Naming System? Historically, Mandiant and Google’s Threat Analysis Group (TAG) maintained distinct tracking systems, relying on parallel naming schemas that grew independently over time. The creation of GTIG has necessitated a new, fused tracking system, and a new naming system. Thinking to the future, GTIG’s new system will rely on cryptonyms. Relying on sequential numbers or disparate identifiers (e.g. APT1) fails to provide defenders the critical context needed to operate quickly. Threat tracking shouldn’t be an exercise in memorization, but rather one of intuition. The new naming convention aligns with industry standard threat actor naming systems. Our New Schema Our new schema utilizes a cryptonym-based approach, employing memorable two-word combinations for each distinct threat actor: The first word is a unique and memorable term chosen to represent the specific actor, particularly names that may have been used in prior public reporting. If no previously used term exists, this word is randomly generated to remove bias, then vetted by our analysts. The second word categorizes threat clusters by motivation, attribution, or activity type based on which category we consider to be most important for defense and response strategies. The table below provides a sample of how threat actor categories will map to the second word in each cryptonym: Origin or Type Group Name People’s Republic of China CASTLE Iran ION North Korea NEPTUNE Russia RELIC Cybercriminal COMET Table 1: Examples of Google’s new threat actor naming system categories We know there are many threat actor tracking schemas in the industry, so we are intentionally seeking to keep this system as simple as possible to streamline operations and facilitate mapping to other naming taxonomies. However, a significant caveat remains: because no two organizations have the exact same visibility into the threat landscape, direct, apples-to-apples comparisons between threat actors are rarely possible. Transitioning to a convention that is simpler to follow and remember is a practical step toward managing a highly intricate tracking problem. A Work in Progress We have initially prioritized renaming several dozen of the most active groups, and will continue this process on a rolling basis. Previous names will remain indexed and searchable in the Google Threat Intelligence (GTI) platform, with MITRE ATT&CK mappings and other vendor aliases preserved, see Figure 1. Figure 1: Threat actor name appearance in GTI platform on initial rollout We will continue to use UNC, or “uncategorized” designations for threat clusters that are still in the early stages of investigation, as described here.
Analysis Summary
# Industry News: Google Unifies Threat Actor Taxonomy Under GTIG
## Summary
Google Threat Intelligence Group (GTIG) has announced a new, unified cryptonym-based naming schema for tracking cyber threat actors. This initiative merges the previously disparate tracking systems of Mandiant and Google’s Threat Analysis Group (TAG) into a single, intuitive taxonomy designed to improve defender response times and cross-industry collaboration.
## Key Details
- **Date:** July 24, 2026
- **Companies Involved:** Google, Mandiant, Google Threat Analysis Group (TAG)
- **Category:** Operational Update / Brand Integration
## The Story
Following the acquisition of Mandiant and the subsequent formation of the Google Threat Intelligence Group (GTIG), the company faced a legacy challenge: two internal units tracking the same global threats using different nomenclature (e.g., Mandiant’s "APT" vs. TAG’s internal identifiers).
To resolve this, GTIG is shifting to a two-word cryptonym system. The first word is a unique identifier (often inherited from historical reporting), while the second word denotes the origin or motivation:
* **CASTLE:** People’s Republic of China
* **ION:** Iran
* **NEPTUNE:** North Korea
* **RELIC:** Russia
* **COMET:** Cybercriminal entities
The system aims to replace sterile, sequential numbering (like APT41) with memorable associations that provide immediate context regarding the threat's profile and likely tactics.
## Business Impact
### For the Companies Involved
- **Efficiency:** Streamlines internal workflows by eliminating the need to bridge two different data sets for the same actor.
- **Brand Consolidation:** Finalizes the integration of Mandiant into the Google ecosystem, presenting a single, authoritative voice to the market.
### For Competitors
- **Setting the Standard:** Google is positioning itself alongside Microsoft (which uses weather-based naming) and CrowdStrike (which uses animal-based naming), forcing smaller players to align with these dominant taxonomies or risk obsolescence.
### For Customers
- **Reduced Cognitive Load:** Clients of Google Threat Intelligence (GTI) will find it easier to communicate threats to non-technical stakeholders using memorable names rather than alphanumeric strings.
- **Data Continuity:** Documentation and historical indices will remain searchable, ensuring no loss of legacy intelligence during the transition.
### For the Market
- **Standardization:** While a single "universal" naming system remains elusive due to differing vendor visibility, Google’s move toward a descriptor-based schema pushes the industry further away from "spreadsheet security" toward intuitive intelligence.
## Technical Implications
The new schema incorporates a "UNC" (Uncategorized) designation for clusters in the early stages of investigation. This allows for technical agility, enabling analysts to track emerging telemetry before full attribution is confirmed. Integration with MITRE ATT&CK mappings ensures that the change in name does not disrupt existing technical workflows or automated detection logic.
## Strategic Analysis
- **Market Positioning:** This moves Google into a "tier one" intelligence role, mirroring the sophisticated branding used by its largest rivals, Microsoft and CrowdStrike.
- **Competitive Advantage:** By including the "motivation/origin" in the name itself (the second word), Google provides "instant intelligence," allowing SOC teams to prioritize response based on the gravitas of a nation-state vs. a criminal actor.
- **Challenges:** The "naming confusion" phase is inevitable. During the rolling update, security teams will have to manage a period where one actor may be referred to by three or four different aliases across hisotrical and current reports.
## Industry Reactions
- **Analyst Opinions:** Analysts generally view this as a necessary "housekeeping" step following the Mandiant acquisition, though some note the irony of "simplifying" the market by adding yet another naming convention.
- **Market Response:** Professional threat hunters have welcomed the move from "sequential numbers" to "intuitive cryptonyms," noting that human memory handles names significantly better than digits during high-stress incidents.
## Future Outlook
- **The End of APT Numbers:** We expect the "APT" designation (pioneered by Mandiant) to slowly sunset in favor of this new "GTIG" schema in mainstream media.
- **Automated Mapping:** Expect a surge in software updates for TIPs (Threat Intelligence Platforms) to handle the new GTIG-to-Alias mapping tables.
## For Security Professionals
Practitioners should update their internal documentation and watch for "bridge" reporting from Google that maps old APT or UNC numbers to the new "CASTLE," "ION," or "COMET" designations. The focus remains on *behavior* (TTPs), but the new naming system should facilitate faster executive briefings and peer-to-peer sharing.