Google revamps hacker group naming conventions, making it easier to identify Chinese groups as 'CASTLE' and Russian groups as 'RELIC'.



Google Threat Intelligence Group (GTIG), Google's threat intelligence team, has revamped its naming conventions for tracking 'threat actors,' such as hacker groups. The new method adds words like 'CASTLE' to the end of names for groups associated with China and 'RELIC' for groups associated with Russia, making it easier to understand the attacker's origins, motives, and types of activities from their names.

Updated Cyber Threat Actor Naming System | Google Cloud Blog

https://cloud.google.com/blog/topics/threat-intelligence/updated-cyber-threat-actor-naming-system?hl=en



Google's top hacker hunter explains why hacking groups get codenames | TechCrunch
https://techcrunch.com/2026/08/08/googles-top-hacker-hunter-explains-why-hacking-groups-get-codenames/


Security companies have long used unique names like 'APT1' and 'Fancy Bear' to continuously track groups that carry out cyberattacks. By continuously tracking attackers' past actions and targets under the same identifier, organizations under attack can quickly determine 'who might be attacking and for what purpose.' Shane Huntley, Chief Technology Officer of GTIG, explained to TechCrunch that understanding attackers' actions and past activities is crucial when considering incident response and defense strategies.

On the other hand, there is the problem that different naming conventions are used by each company tracking cyberattacks. Furthermore, at Google, the acquired security company Mandiant and Google's Threat Analysis Group (TAG) were tracking attackers in different ways. According to Google, the establishment of GTIG necessitated the integration of both tracking systems. According to John Hultquist, the principal analyst at GTIG, Google was tracking more than 5,000 'activity clusters,' which are sets of attacks, and it had become difficult to manage them by simply remembering sequential numbers or multiple identification methods.

Therefore, GTIG adopted a new naming convention that combines two easy-to-remember words. The first word is a unique name used to distinguish the attacker. If there is a name that has been established from past public information, it is retained whenever possible, and if there is no suitable name, GTIG analysts review randomly generated candidates to avoid bias.



The second word represents the attacker's origin, motives, and type of activity. Specifically, threat actors associated with China are 'CASTLE,' Iran is 'ION,' North Korea is 'NEPTUNE,' and Russia is 'RELIC.' Cybercriminals are assigned 'COMET.' By allowing attackers to gain at least a minimum level of clues just by looking at their names, the burden of memorizing traditional names like 'APT + number' is reduced.

However, even with the introduction of the new method, the names of hacker groups across the entire industry will not be standardized. Because each security company has different data collection capabilities and observation scopes, even if different companies are tracking the same attacker, they may not be able to treat them as the exact same group. Huntley also explained that 'nobody has a complete grasp of the overall threat,' and that simply sharing information between companies will not completely eliminate differences in naming conventions.

GTIG is initially transitioning to new names for dozens of the most active groups. The old names will remain searchable on Google Threat Intelligence (GTI), and their correspondence with ' MITRE ATT&CK ,' which organizes cyberattack methods, as well as alternative names used by other companies, will be retained. Furthermore, groups whose identities cannot be fully classified as investigations have just begun will continue to use the identification name 'UNC.' Google says it will continue to change names in stages to make tracking complex threat actors easier to understand.

in Security, Posted by log1d_ts