Google’s top hacker hunter explains why hacking groups get codenames
Google has replaced Mandiant’s numbered APT labels with a new naming system for hacking groups, intended to make cyber-threat reporting easier to understand and track. The change matters because security teams rely on consistent knowledge of attackers’ past behaviour, targets and methods to recognise incidents quickly and improve their defences.
Under the new approach, groups receive a memorable random first name followed by a country-coded second word: Castle denotes China, Ion Iran, Neptune North Korea and Relic Russia. Google says it now tracks more than 5,000 “activity clusters”, reflecting the growth of state-backed cyber operations worldwide; however, its threat-intelligence chief notes that criminal and mercenary groups remain harder to follow because their members, customers and structures change frequently.
- Google simplified its hacking-group naming system.
- Names help defenders identify familiar attacker behaviour.
- Google tracks over 5,000 cyber activity clusters.