Overview
- Google’s Threat Intelligence Group has begun rolling out a new naming system and has renamed several dozen active threat groups while keeping old aliases searchable in its platform.
- Each tracked actor now gets a two-word cryptonym where the first word is a memorable group name that preserves prior public labels or is randomly generated when no prior name exists.
- The second word is a category token that signals assessed motive or origin, using CASTLE for China, ION for Iran, NEPTUNE for North Korea, RELIC for Russia, and COMET for cybercrime.
- The change follows Google’s merger of Mandiant and its Threat Analysis Group and joins industry mapping efforts such as the Microsoft and CrowdStrike collaboration to translate between rival naming systems.
- Google says the system should speed recognition and cross-vendor mapping for defenders but warns it cannot remove differences caused by each organization’s limited and varied visibility and will keep UNC for undecided clusters.