Google’s top hacker hunter explains why hacking groups get code names
Google announced that its internal hunting team, led by CTO Shane Huntley, will now label threat actors with a two‑part moniker: a random first name and a second word whose initial signals the group’s nation‑state origin—“Castle” for China, “Ion” for Iran, “Neptune” for North Korea, and “Relic” for Russia. The change folds the legacy Mandiant naming convention into a single Google schema and applies to more than 5,000 activity clusters the company monitors worldwide. Huntley argues that a consistent label lets defenders quickly recognize an adversary’s playbook, prioritize mitigations, and accelerate investigations when a breach occurs.
The move arrives amid a decade‑long patchwork of naming approaches, from the original APT‑number system pioneered by Mandiant (now a Google subsidiary) to bespoke tags used by firms like CrowdStrike and FireEye. While the industry has long coveted a universal taxonomy, each vendor’s visibility into threat traffic differs, making full alignment elusive. Google’s simplified scheme reflects a broader push for clearer communication, especially as state‑backed actors such as Lazarus (North Korea) become household names, while criminal‑for‑hire outfits remain fluid and harder to pin down.
Practical consequences will surface quickly. Security teams that already ingest Google‑ or Mandiant‑generated alerts can now map incidents to a single, more intuitive identifier, reducing the cognitive load during triage. However, the persistence of parallel naming systems means analysts must still cross‑reference multiple databases, and any mis‑attribution could inflame diplomatic sensitivities. Watch for adoption signals from other major threat intel vendors; if they begin mirroring Google’s suffix convention, the market may coalesce around a de‑facto standard. Conversely, continued divergence would keep the “one‑stop‑shop” list essential for the foreseeable future.
Key Takeaways
Google’s new taxonomy swaps cryptic APT numbers for memorable first names plus country‑coded suffixes, covering over 5,000 tracked clusters.
The change consolidates Google’s legacy Mandiant naming with its own Threat Intelligence Group, aiming to cut confusion for internal and external researchers.
Industry fragmentation persists because each firm’s data set is unique, limiting the feasibility of a single universal naming system.
Adoption by other intel providers will determine whether Google’s scheme becomes a broader standard or remains one of many parallel taxonomies.
About the Source
This analysis is based on reporting by TechCrunch. Here is a short excerpt for context:
Google recently changed how it refers and assigns names to hacking groups. TechCrunch spoke with one of the world’s foremost experts on tracking hackers to understand why companies give hackers codenames.Read the original at TechCrunch