GBHackers

Google Launches Unified Cryptonym-Based Naming System for Threat Actors


Google Threat Intelligence Group (GTIG) has introduced a unified cryptonym-based naming system for cyber threat actors, aiming to simplify attribution, improve analyst workflows, and eliminate inconsistencies between legacy tracking conventions used across Google’s security teams.

The initiative follows the integration of Mandiant and Google’s Threat Analysis Group (TAG) into GTIG. Before the merger, both organizations maintained independently developed systems for identifying and tracking threat clusters.

This created a recurring challenge for defenders: the same activity could be documented under multiple names, forcing security teams to manually reconcile overlapping aliases across reports, intelligence platforms, and detection workflows.

Google Launches Unified Cryptonym-Based Naming System

GTIG’s new model replaces those fragmented identifiers with memorable, two-word cryptonyms designed to convey both a unique group identity and high-level attribution context.

Under the updated schema, the first word acts as a distinct identifier for the threat actor. Where possible, GTIG retains a term already associated with the group in public reporting to preserve recognition and continuity.

Threat actor name appearance in GTI platform on initial rollout (Source: Google)

If no widely established identifier exists, Google generates a randomized name and subjects it to analyst review intended to reduce bias and prevent potentially misleading associations.

The second word identifies the group’s category, such as its suspected nation-state origin, criminal motivation, or operational type.

Origin or TypeGroup Name
People’s Republic of ChinaCASTLE
IranION
North KoreaNEPTUNE
RussiaRELIC
CybercriminalCOMET

The Russian state-linked actor commonly known as APT44 or Sandworm will now be tracked by Google as SANDWORM RELIC. The “SANDWORM” identifier retains the group’s well-known public designation, while “RELIC” provides an immediate indication of its assessed Russian state affiliation.

Sandworm has been active since at least 2004 and has accumulated numerous aliases over time, including Dark Basin, Frozenbarents, GreyEnergy, Hades, Inedibleochotense, and Quedagh.

Google said the updated naming framework is intended to function as an intuitive operational reference rather than another system analyst.

The company also emphasized that the framework is designed to map more cleanly to naming schemes used by other security vendors. However, GTIG acknowledged that one-to-one comparisons across threat intelligence providers will remain imperfect.

Organizations often observe different infrastructure, malware, victimology, and operational patterns, meaning they may define or split threat clusters differently.

The naming system should therefore be viewed as a practical standardization measure within Google’s ecosystem, rather than a universal solution to the broader challenge of cyber threat attribution.

GTIG will initially apply the new cryptonyms to several dozen of the most active threat groups, with additional actors scheduled for renaming over time.

Legacy identifiers will remain indexed and searchable in the Google Threat Intelligence platform, preserving historical research and supporting analysts accustomed to older terminology.

Google will also retain mappings to MITRE ATT&CK techniques and aliases assigned by other vendors, helping organizations maintain continuity in reporting, detection content, and intelligence integrations.

Security teams using Google Threat Intelligence feeds should monitor the transition closely. Updating internal threat actor references, enrichment workflows, and detection-rule documentation will help prevent confusion as the new cryptonyms begin appearing in alerts and dashboards.

ALERT: 20+ government sites delivered malware to businesses and citizens. See full attack research to check your own exposure.



Source link