Cybersecurity4 mins read

Why Google Is Changing the Way It Names Hacking Groups

Google has revamped how it assigns codenames to hacking groups, aiming to make threat tracking clearer for security teams inside and outside the company.

Google Is Replacing APT Numbers With More Memorable Names

Google recently revamped how it refers to and assigns names to hacking groups. The older Mandiant-style system used labels such as APT1 and APT41, but Google’s updated approach gives groups a memorable first name plus a second word whose initial signals the country of origin.

In the system described by TechCrunch, examples include Castle for China, Ion for Iran, Neptune for North Korea, and Relic for Russia. The goal is clarity: fewer hard-to-track labels and a naming structure that security researchers can understand more quickly.

Why Codenames Matter in Real Incidents

Hacker names are not just branding. Shane Huntley, chief technology officer of Google Threat Intelligence Group, told TechCrunch that naming and tracking groups consistently helps defenders understand who is attacking whom and how those attackers typically operate.

That context can help organizations recognize threats faster, prepare defenses, investigate incidents more promptly, and assess coverage against known behaviors. In short, consistent naming turns scattered threat activity into a more usable map for response teams.

The Cyber Threat Map Has Become Harder to Manage

The cybersecurity industry has named hacking groups for more than a decade, but different companies often use different labels for the same or similar activity. TechCrunch notes that even industry insiders can struggle to keep track, which is why centralized reference resources exist to help professionals, policymakers, journalists, and the public make sense of who is who.

Google now tracks more than 5,000 activity clusters in several countries, according to John Hultquist, chief analyst at Google Threat Intelligence Group. Huntley also said there are very few developed nations that do not have their own cyber capabilities and hacking groups.

Why One Universal Naming System Remains Difficult

A common question is why all companies do not simply use the same hacker codenames. Huntley told TechCrunch the reality is that each company has a different view of threat groups because each has its own data and telemetry.

State-sponsored hackers can be easier to track because their targets and activities tend to be more consistent. Cybercriminal groups, hackers-for-hire, and spyware makers can be harder to categorize because members, customers, and operations may shift across regions and over time.

Key Takeaway for Security Teams

Google’s unified naming scheme reduces one layer of confusion by bringing together the old Threat Analysis Group and Mandiant approaches. It does not solve every attribution challenge, but it gives researchers and defenders a cleaner framework for discussing threats.

The practical lesson is simple: names matter when they help teams connect behavior, history, targets, and response. For organizations, the value is not the codename itself but the faster understanding that comes with consistent tracking.

Discover More