Google Scraps APT Numbers for Country-Tied Hacker Monikers
Google’s in-house hacker-hunting arm, the Threat Intelligence Group, is ditching the once-ubiquitous APT numbering system made famous by Mandiant. In its place, the company is adopting a schema that pairs a memorable first name with a second word whose first letter signals a nation of origin: Castle for China, Ion for Iran, Neptune for North Korea, and Relic for Russia. The change aims to bring order to an increasingly crowded threat landscape where Google now tracks more than 5,000 distinct activity clusters, according to chief analyst John Hultquist.
Shane Huntley, the group’s chief technology officer, told TechCrunch that the older naming conventions were never designed for the volume of groups analysts now face. “We were not expecting to have as many threat groups as we do today,” he said. By consolidating the nomenclature previously split between Google’s own Threat Analysis Group and Mandiant—acquired in 2021—the company hopes to give both internal researchers and external users of its threat reports a simpler, faster way to recognize actors and their likely behaviors.
The naming is far from academic. Knowing that an attacker is a North Korean state-sponsored group, for example, immediately tells incident responders what typical goals, tools, and persistence tactics to anticipate. Huntley stressed that such baseline understanding helps organizations react faster after a breach, improve detection rules, and ultimately shrink the window of damage.
Behind the Vexing Art of Tracking Thousands of Threat Actors
The Operational Case for a Unified Naming Scheme
For a company that ingests billions of security signals daily, a coherent internal taxonomy is not just convenience—it’s operational necessity. When analysts from different parts of Google’s ecosystem (Android security, Gmail abuse, Mandiant consulting) can immediately align on a single label, correlation improves, false positives drop, and attribution timelines shrink. The new system’s deliberate use of country-coded second words also bakes geopolitical context directly into the name, saving precious minutes during active incidents.
Why a Universal Threat Lexicon Remains Elusive
Despite perennial calls for the cybersecurity industry to standardize names—think of Fancy Bear also being known as APT28, Sofacy, Sednit, and dozens more—Google’s move underscores why convergence is so hard. Huntley acknowledged that every firm sees threat groups through its own data lens. “No one has perfect visibility,” he said. Different telemetry produces different attribution breadcrumbs, and a name that perfectly captures one company’s view may be misleading for another. Google’s revamp reduces one source of fragmentation, but it does not eliminate the structural barrier to a single, industry-wide lexicon. For defenders, that means cross-referencing tools like the MITRE ATT&CK group list will remain essential.
What State-Linked Actors Tell Us About the Threat Landscape
The article also surfaces a subtle shift in difficulty: Huntley noted that tracking state-sponsored hackers is actually easier than following cybercriminal gangs or hack-for-hire groups. Government-linked groups tend to have stable mission sets and persistent infrastructure, while criminal outfits splinter, re-brand, and share members across campaigns. Google’s new naming system, by explicitly tying groups to nation-states, implicitly prioritizes the clearer—and arguably more geopolitically consequential—part of the threat picture. This focus could shape how enterprises allocate their threat-hunting resources, nudging them toward actors where a name actually carries predictive value.
What Security Teams Should Do With Google's New Naming System
For corporate security teams, the naming change is not academic: it directly affects the threat reports, indicators of compromise (IOCs), and intelligence feeds that come from Google and Mandiant. To get the most value from the shift, practitioners should:
- Update internal actor taxonomies to map existing APT labels to Google’s new country-pair format—Castle (China), Ion (Iran), Neptune (North Korea), Relic (Russia)—so that alerts and investigations align with the latest Mandiant reports.
- Re-evaluate threat intelligence platform (TIP) correlation rules. Because multiple naming schemes will persist across vendors, TIPs that can normalize actor identities (e.g., linking Microsoft’s “Strontium” with Google’s new “Relic” designation) will significantly reduce analyst fatigue.
- Prioritize response playbooks for state-linked groups. Huntley’s observation that government-backed actors are more consistent means that Google’s new names can serve as reliable shortcuts for institutionalizing pre-built investigation and containment procedures.
Risk & Opportunity Assessment
| Commercial Risk | Low | A naming taxonomy change does not directly threaten Google’s revenue or operations; if poorly executed, it could cause brief confusion among threat intelligence customers, but the impact is minor. |
| Competitive Risk | Medium | Rival threat intelligence providers (CrowdStrike, Microsoft, Recorded Future) may see Google’s more accessible naming as a competitive differentiator for Mandiant services, pressuring them to simplify their own schemas. |
| Regulatory Risk | Low | Naming conventions are not currently subject to cybersecurity regulations; no compliance changes are triggered. |
| Reputation Risk | Low | Over-simplification could draw criticism if important nuance is lost, but the industry broadly welcomes clearer names; the risk is minimal. |
| Technology Disruption | Low | The change is procedural rather than technological; it does not disrupt existing detection or response technologies. |
| Commercial Opportunity | Medium | A more intuitive naming system can make Google’s threat intelligence reports more consumable, potentially attracting enterprises that previously found Mandiant reports opaque, and strengthening the value proposition of Google Chronicle and other security products. |
Comments 0