Article
Cybersecurity Tech Giants

Google revamps hacker naming, swaps APT numbers for two-word codenames

by TechDefused Newsroom
A figure in a dark hoodie reaches out with a hand, while streams of red binary code cascade down in front of them, creating a digital and ominous atmosphere. The blurred background suggests an environment focused on technology and cybersecurity. aiImage created using AI — Midjourney

Google revamped its naming system for hacking groups, ditching the older numeric APT labels for two-word codenames revamped its naming system.

The change aims to reduce confusion as Google now tracks more than 5,000 activity clusters, a volume the company says outstrips older taxonomies tracks more than 5,000 activity clusters.

"We were not expecting to have as many threat groups as we do today," said Shane Huntley, chief technology officer of Google's Threat Intelligence Group.

Under the new approach a memorable first name is paired with a second word whose initial signals the country of origin, for example Castle for China, Ion for Iran, Neptune for North Korea and Relic for Russia Castle for China.

Google says the goal of naming is to give defenders a baseline understanding of an actor's behaviour so organisations can recognise and respond to incidents faster baseline understanding.

Huntley added that state-sponsored groups tend to be more consistent and therefore easier to track than cybercriminal gangs and hackers‑for‑hire, which splinter or serve many customers easier to track.

He also argued that different firms will keep using different labels because "no one has perfect visibility" into every intrusion no one has perfect visibility.

The naming update arrives as Google researchers report attackers using phone calls to compromise employees at major U.S. financial firms phone calls to compromise employees and as data shows ransom-seeking groups have targeted U.S. private equity and firms including Blackstone targeted U.S. private equity.

By unifying the legacy Mandiant labels with Google's internal Threat Analysis Group, Huntley said there is now one fewer naming scheme for defenders to cross‑reference unifying the naming scheme.

by TechDefused Newsroom