Google Threat Intelligence Group (GTIG) announced a new unified cryptonym-based naming taxonomy for threat actor tracking, merging the previously separate Mandiant and TAG naming systems. The schema assigns each actor a memorable two-word cryptonym, where the second word denotes category (e.g., origin/motivation such as nation-state attribution or cybercriminal activity), improving cross-platform consistency and reducing reliance on sequential identifiers like APT numbers.
sandworm
1 post
Updated Cyber Threat Actor Naming System