Updated Cyber Threat Actor Naming System

Google Threat Intelligence Group (GTIG) is rolling out a unified naming schema for threat actors, replacing the separate systems previously used by Mandiant and Google’s Threat Analysis Group (TAG).

The new taxonomy relies on cryptonyms—memorable two-word combinations—where the first word is a unique term (often drawn from prior public reporting or randomly generated to avoid bias) and the second word categorizes the threat cluster by motivation, origin, or activity type.

Examples include: China → CASTLE, Iran → ION, North Korea → NEPTUNE, Russia → RELIC, and cybercriminal → COMET.

The system is designed to be intuitive and facilitate cross-platform mapping, though the source notes that direct apples-to-apples comparisons between actors are rarely possible due to differing visibility across organizations.

The transition is incremental: several dozen of the most active groups have been renamed first, with previous names still indexed and searchable in the Google Threat Intelligence (GTI) platform, and MITRE ATT&CK mappings and other vendor aliases preserved.

UNC (uncategorized) designations will continue to be used for clusters still under early investigation.

Updated Cyber Threat Actor Naming System

View Original