IT-PUB NEWS

Google changes hacker group names to cut confusion

09.08.2026 11:03 • Author: IT-PUB
Google changes hacker group names to cut confusion

The company is retiring Mandiant’s older APT-style labels for a two-part naming system as it tries to make threat tracking easier to follow.

Google has changed the way it names hacking groups, replacing its older numbering system with a simpler format meant to make cyber threat tracking easier to follow. The shift matters because these labels are used by security teams, journalists, policymakers, and others trying to understand who is behind an attack and how different threat actors operate. It also brings back a familiar cybersecurity problem: the same group can end up with different names depending on who is tracking it. That makes comparing reports and following threat activity harder than it should be.

Google retires Mandiant's old APT labels

Last month, Google introduced a new naming system for hacking groups. It replaces the older APT-style labels such as APT1 and APT41 that were used by Mandiant, the security firm now part of Google.

Mandiant was the first to adopt a formal naming scheme, but Google now says the numbered format is being retired in favor of something more readable. Under the new system, each hacking group gets a two-part name. The first is a memorable random word, while the second points to the country of origin through its first letter.

Google’s examples are Castle for China, Ion for Iran, Neptune for North Korea, and Relic for Russia. The company says the goal is not branding, but clarity.

Google says clearer names help defenders move faster

Shane Huntley, chief technology officer of Google Threat Intelligence Group, said the revamp was needed to make things clearer for researchers inside and outside the company. He said Google had not expected the number of threat groups to grow as much as it has since the early 2010s, when companies first began publishing reports about cyberattacks and the actors behind them.

That growth has made the landscape harder to navigate. According to John Hultquist, chief analyst at Google Threat Intelligence Group, Google now tracks more than 5,000 “activity clusters” in several countries. As IT-PUB News notes, that scale helps explain why a naming system can become a practical issue, not just a matter of terminology.

Huntley said the naming system is not just an academic exercise. The idea is to create a shared baseline for understanding who is attacking whom and how. If defenders can identify a group faster, they may be able to prepare for an attack, stop it earlier, or investigate an incident more effectively.

He said that once an organization is targeted, knowing a group’s behavior, goals, and past activity can be critical. In his example, understanding how the North Korean government hackers known as the Lazarus Group operate gives defenders a starting point for response.

State-backed groups are easier to follow than cybercrime crews

Huntley also drew a distinction between different kinds of threat actors. He said state-sponsored hacking groups are generally easier to track because they tend to show more consistent targets and patterns of activity.

Cybercriminal groups are often harder to follow, he said, because their members may change, split apart, or operate in a more fluid way. Hacker-for-hire groups and spyware makers can be even more difficult to pin down, since they may have customers in different parts of the world.

That makes naming and tracking a practical tool for the security industry, but not a perfect one. Labels can help organize a complicated field, yet they do not remove the uncertainty that comes with trying to map hidden online activity.

Google still cannot solve the industry's naming overlap

Whenever a company introduces a new naming system, the same complaint tends to surface: why not use one shared set of codenames across the industry?

Huntley said that is easier to ask than to solve. In his view, each company sees threat groups through its own data and telemetry, so each one builds a slightly different picture. He argued that this cannot be fixed simply by sharing more information.

“No one has perfect visibility,” he said. “We are building our model and our best understanding, but we will never know everything about what’s going on.”

That remains the central tension in Google’s change. The company wants a system that is easier to understand, but the wider cybersecurity world still has to work with incomplete information and multiple naming traditions at the same time.

Google folds separate naming approaches into one

Google says the new approach also brings together the naming methods used by its former Threat Analysis Group and by Mandiant, removing another layer of confusion for people following cyber threats.

For researchers and reporters, that may make the work a little easier. For everyone else, the broader problem remains: cyberattacks are being carried out by a growing number of groups, and even the labels used to describe them can add to the confusion. Google’s revamp does not settle that on its own, but it shows how much effort now goes not just into detecting attacks, but into making sense of the actors behind them.

 


Аудит Сайту для малого та середнього бізнесу за $50