Google’s New Hacking Group Naming System Explained

Matilda
5 Min Read

For over a decade, cybersecurity companies have assigned memorable names to hacking groups. Some—like Fancy Bear—became mainstream due to high-profile attacks. Others remain obscure, known only to industry insiders.

The naming chaos makes it difficult for even seasoned professionals to keep track. Different firms use different naming conventions, which is why resources like threat group trackers exist to help security teams, policymakers, journalists, and the public identify who’s who.

Now, Google has revamped its naming system for hacking groups, aiming to bring clarity and consistency to the field. Here’s what changed and why it matters for cybersecurity.

What Google’s New System Looks Like

Gone are the days of APT1, APT41, or other numbered designations—the system pioneered by Mandiant, which Google now owns. Instead, Google’s new naming formula is refreshingly simple:

· A memorable random first name

· A second word indicating country of origin, with specific initial letters:

· Castle = China

· Ion = Iran

· Neptune = North Korea

· Relic = Russia

According to Shane Huntley, Chief Technology Officer of Google Threat Intelligence Group, the revamp was essential to bring clarity to researchers both inside Google and across the broader security community.

Why Consistent Hacker Names Matter

The goal of naming hacking groups isn’t just academic. It provides a baseline understanding of who is attacking whom, and how. This helps organizations:

· Recognize threats faster

· Prepare appropriate defenses

· Stop attacks before they succeed

· Investigate incidents more efficiently

“If you actually get hacked by them or you’re dealing with some incident, knowing how that actor behaves, what they do, what they’ve done in the past, all of these details become critically important to help the response and also work out your coverage against these threats,” Huntley told TechCrunch.

For example, knowing that North Korea’s Lazarus Group targets financial institutions with specific malware patterns gives defenders an immediate starting point for incident response.

Tracking State Hackers vs. Cybercriminals

Huntley noted that tracking state-sponsored hackers is actually easier than tracking cybercriminal groups. Government hackers tend to have consistent targets and predictable behaviors. Cybercriminals, by contrast, are more amorphous—members come and go, groups splinter, and operations shift frequently.

Hacker-for-hire groups and spyware vendors present their own challenges, serving many customers across different regions and leaving complex footprints that complicate tracking efforts.

The Challenge of Unifying Names

A common question is: Why can’t all companies use the same codenames?

Huntley explained that every organization has different visibility into threat activity based on their unique data and telemetry. One firm might see a group targeting Western financial institutions; another might observe the same group’s espionage operations in Asia. These incomplete views lead to different naming decisions.

“No one has perfect visibility,” Huntley said. “We are building our model and our best understanding, but we will never know everything about what’s going on.”

The Scale of Modern Cyber Threats

Google now tracks more than 5,000 “activity clusters” across multiple countries, according to John Hultquist, chief analyst at Google Threat Intelligence Group. Huntley added that very few developed nations lack their own cyber capabilities and hacking groups.

What started as a manageable exercise in the early 2010s—when companies first began publishing reports on cyberattacks—has exploded into a vast ecosystem that demands systematic organization.

By unifying Google’s old Threat Analysis Group with Mandiant’s approach, there’s now one fewer naming scheme to remember. For everything else, researchers still rely on exhaustive reference lists to map the ever-growing threat landscape.

What This Means for Defenders

Google’s new naming system represents a practical step toward better threat intelligence sharing. While complete agreement across the industry remains unlikely, simplifying internal naming helps Google’s own teams respond faster and more effectively to emerging threats.

For cybersecurity professionals, the takeaway is clear: Whether you’re tracking “Fancy Bear” or Google’s new “Castle” designations, understanding who’s behind the attack gives you a critical advantage in protecting your organization.

Share This Article
Leave a Comment