Google goes it alone with a new cybercrime crew taxonomy
Google has unveiled its own naming system for cybercrime groups, breaking from a Microsoft- and CrowdStrike-led push for an industry-wide standard. The move comes after Google's 2022 acquisition of Mandiant, whose threat intelligence operations have now merged with Google's own into a single unit called the Google Threat Intelligence Group (GTIG), prompting the need for one consistent naming convention across the combined team. The decision matters because security researchers currently use wildly differing names for the same threat actors, making it harder for organisations using multiple vendors' tools to work out which groups they are actually defending against.
Under Google's new two-word system, the first word is a unique identifier for the specific group, either reusing an existing name or generating one at random "to remove bias," while the second word categorises the actor by motivation or origin. Google has assigned CASTLE to Chinese state-linked crews, ION to Iranian actors, NEPTUNE to North Korean groups, RELIC to Russian actors, and COMET to financially motivated criminals with no state backing. This follows a 2025 attempt by Microsoft and CrowdStrike to unify naming across the industry, which Google was reportedly interested in joining at the time, and echoes past criticism from China's CVERC over Western naming choices such as "Typhoon" or "Panda" for Chinese hacking groups.
- Google launches its own cybercrime naming scheme via GTIG
- Abandons earlier Microsoft/CrowdStrike push for unified industry naming
- New names include CASTLE (China), ION (Iran), NEPTUNE (North Korea), RELIC (Russia), COMET (criminal)