Updated Cyber Threat Actor Naming System
Google Threat Intelligence Group (GTIG) announced a new unified cryptonym-based naming taxonomy for threat actor tracking, merging the previously separate Mandiant and TAG naming systems. The schema assigns each actor a memorable two-word cryptonym, where the second word denotes category (e.g., origin/motivation such as nation-state attribution or cybercriminal activity), improving cross-platform consistency and reducing reliance on sequential identifiers like APT numbers.
Detection / HunterAnthropic
What Happened
Google's threat intelligence team is changing how they name hacking groups they track, moving to a new system of memorable two-word codenames instead of older naming schemes like 'APT1'. This change affects security researchers and organizations that rely on Google's threat intelligence reports and platform, not the general public or specific victims. It matters because consistent, memorable naming helps defenders quickly recognize and respond to known threats, but it can also cause temporary confusion as familiar names (like APT44) are replaced with new ones (like SANDWORM RELIC). Security teams should update their internal threat tracking references and cross-reference old and new names, which Google says will remain searchable together during the transition.
Key Takeaways
- Google Threat Intelligence Group (GTIG) is rolling out a new unified cryptonym-based naming system for threat actors, replacing separate Mandiant and TAG naming schemas.
- The new naming convention uses two-word combinations: a unique first word for the actor and a second word indicating motivation/attribution/origin (e.g., CASTLE for China, ION for Iran, NEPTUNE for North Korea, RELIC for Russia, COMET for cybercriminal groups).
- APT44 is being renamed to SANDWORM RELIC under the new schema, with prior aliases (Dark Basin, Frozenbarents, Greyenergy, Hades, Inedibleochotense, Quedagh) preserved for mapping.
- Previous names, aliases, and MITRE ATT&CK mappings remain indexed and searchable in the Google Threat Intelligence (GTI) platform during the transition.
- The rollout is a rolling, ongoing process starting with several dozen of the most active tracked groups; UNC (uncategorized) designations will continue to be used for early-stage threat clusters.
Vulnerabilities (CVEs)
None identified.
Attack Chain
N/A - This article is an administrative/informational announcement about threat actor naming conventions and does not describe an attack chain.
Detection Availability
- YARA Rules: No
- Sigma Rules: No
- Snort/Suricata Rules: No
- KQL Queries: No
- Splunk SPL Queries: No
- EQL Queries: No
- Other Detection Logic: No
This article does not provide any detection rules, signatures, or queries. It is an announcement of a threat actor naming taxonomy change.
Detection Engineering Assessment
| Dimension | Rating | Rationale |
|---|---|---|
| EDR Visibility | None | The article contains no technical attack details or malware behavior; it is purely about naming convention changes. |
| Network Visibility | None | No network indicators, infrastructure, or attack techniques are described. |
| Detection Difficulty | Easy | There is no detection use case here; the article is administrative in nature. |
Hunting Hypotheses
| Hypothesis | Telemetry | ATT&CK Stage | FP Risk |
|---|---|---|---|
| No hunting hypothesis applies as this article does not describe attacker behavior, TTPs, or IOCs to hunt for. | N/A | N/A | N/A |
False Positive Assessment
Low - This is an informational naming convention change with no technical detection content, so there is minimal false positive risk associated with this article.
Recommendations
Immediate Mitigation
- Consider updating internal threat intelligence documentation and tracking systems to cross-reference old threat actor names (e.g., APT44) with new cryptonym designations (e.g., SANDWORM RELIC); verify against your organization's incident response runbook and team escalation paths before acting.
- Evaluate whether your threat intelligence platform integrations need updates to ingest or map the new Google naming taxonomy alongside existing vendor aliases.
Infrastructure Hardening
- N/A
User Protection
- N/A
Security Awareness
- Consider briefing threat intelligence and SOC analysts on the new naming convention to avoid confusion when consuming Google/Mandiant reporting.
- Evaluate whether internal playbooks, dashboards, or ticketing systems referencing legacy actor names (e.g., APT numbers) should be updated to include new cryptonym mappings.