Advertisement

Google’s solution to hacker name confusion? Yet another naming system

APT-number conventions are out, cryptonyms are in, and security teams now have one more naming system to keep straight.
Listen to this article
0:00
Learn more. This feature uses an automated voice, which may result in occasional errors in pronunciation, tone, or sentiment.
It this APT29? Or Velvet Chollima? Or Volt Typhoon? Or Sandworm Relic? Can CISOs keep up? (Pexels)

If you are a CISO, here is a new problem for the pile: Do I worry more about Sandworm Relic or Strawberry Tempest?

Last week, Google Threat Intelligence Group joined a list of rivals in changing how it names hackers, replacing years of split naming systems with a single set of code names built around memorable word pairs.

The company said in a blog post that the change merges two systems that had grown apart for years inside Google: Mandiant, the security firm Google bought in 2022, and its in-house Threat Analysis Group. Combining those units left Google with overlapping names for the same hacking groups, a problem the new system aims to fix.

“Threat tracking shouldn’t be an exercise in memorization, but rather one of intuition,” the post reads.

Each tracked group will now get a two-word name. The first word is a distinct term meant to be easy to recall, often pulled from names already used in past reporting on a specific group. When no such name exists, researchers will generate one at random and have analysts check it before use. The second word sorts each group by category, such as country of origin or motive. In Google’s published examples, CASTLE pairs with groups tied to China, ION with Iran, NEPTUNE with North Korea, RELIC with Russia, and COMET with financially motivated threat actors not tied to a nation-state.

The approach echoes one CrowdStrike has long been known for. CrowdStrike pairs a specific term with an animal tied to a country or motive: PANDA for China, BEAR for Russia, SPIDER for cybercriminals, JACKAL for hacktivists. Google’s system swaps the animals for words like CASTLE and NEPTUNE but follows the same basic structure, down to the argument for why it works: A two-part name carries more information than a bare country label or number, and it can change as attribution is fine-tuned.

Advertisement

Microsoft took its own turn at a naming overhaul in April 2023, dropping a system built on chemical elements, trees and volcanoes in favor of weather terms. Under that system, Typhoon marked China, Blizzard marked Russia, Sandstorm marked Iran, and Tempest marked financially motivated cybercriminals. The switch produced names that drew as much attention for their sound as their substance, among them Strawberry Tempest, Pumpkin Sandstorm and Pistachio Tempest. Industry experts bristled over the change, saying the names compared the groups to ice cream flavors or cocktails.

By 2025, the industry’s naming sprawl had become enough of a shared headache that two of the biggest players in it agreed to try to sort it out together. Microsoft and CrowdStrike announced a joint mapping effort in June of that year, pairing Microsoft’s weather names with CrowdStrike’s animal names for the same tracked groups, with Google, Mandiant and Palo Alto Networks Unit 42 also signed on to contribute. Both companies were careful to say the project was not an attempt to force the industry onto one naming system, just to make the existing ones easier to translate between.

Google‘s rollout starts with several dozen of the most actively tracked hacking groups, with more to follow over time. Older names will stay searchable within Google’s threat intelligence platform, alongside mappings to the MITRE ATT&CK framework and to the naming systems used by other vendors. 

The company says groups will keep carrying “UNC,” for uncategorized, if it is still too early to identify exactly where a group fits in this taxonomy.

Greg Otto

Written by Greg Otto

Greg Otto is Editor-in-Chief of CyberScoop, overseeing all editorial content for the website. Greg has led cybersecurity coverage that has won various awards, including accolades from the Society of Professional Journalists and the American Society of Business Publication Editors. Prior to joining Scoop News Group, Greg worked for the Washington Business Journal, U.S. News & World Report and WTOP Radio. He has a degree in broadcast journalism from Temple University.

Latest Podcasts