CISOOnline

Google creates another set of names for threat actors

The new method of naming will involve a two-word approach: The first word will refer to motivation, attribution, or activity type, while the second word will represent the specific threat actor, for example, threats from China will end with “CASTLE,” while those from Russia will end with “RELIC.” If a threat group is not believed to be state-sponsored, then the last word will be “COMET.”

Google has already created new names for existing threat groups: TEMP.Tick is now TICK CASTLE, while FIN11 is now RAZOR COMET.

Rather than coming up with a whole new naming scheme, Google could have just standardized on one of its two internal systems. Or adopt the one Microsoft created in 2023. Or continue to work with industry attempts to create a common taxonomy as it said it would do in 2025.



Source link