
For over ten years, the cybersecurity sector has been assigning unique names to various hacking groups, some of which, like Fancy Bear, have gained notoriety due to their high-profile attacks. However, many groups remain obscure, even to industry insiders, as each organization tends to adopt its own naming conventions. To tackle this confusion, Google has recently revamped its naming system for these hacker collectives. The previous alphanumeric designations, such as APT1 or APT41, which originated from Mandiant—now a part of Google—are being replaced with a more straightforward approach. Each hacking group will now be given a memorable first name, followed by a second term that signifies its country of origin: for instance, Castle for China, Ion for Iran, Neptune for North Korea, and Relic for Russia. Shane Huntley, the Chief Technology Officer of Google’s Threat Intelligence Group, emphasized that this update was essential for enhancing clarity among security researchers, both internally and externally. Since the early 2010s, as reports on cyberattacks began to proliferate, the number of identified threat groups has skyrocketed, making it increasingly difficult to maintain an overview of the landscape. Currently, Google monitors over 5,000 distinct 'activity clusters' across various nations, as noted by John Hultquist, the Chief Analyst at Google Threat Intelligence Group. Huntley remarked that very few developed countries lack their own cyber capabilities, highlighting the global nature of these threats. The rationale behind naming these hacking factions extends beyond mere classification. It serves as a foundational tool for understanding the dynamics of cyber threats, enabling organizations to identify and respond swiftly to potential attacks. Huntley pointed out, "If you get hacked by them or are involved in an incident, understanding the actor's behavior and historical context is crucial for effective response and threat mitigation." Moreover, knowledge of groups like North Korea's Lazarus Group—including their typical objectives and affiliations—provides defenders with essential insights to combat these threats. While tracking state-sponsored hackers poses challenges, it is generally less complex than monitoring cybercriminal organizations, which often have fluid membership and activities. A prevalent question arises regarding the inconsistency in naming conventions among different organizations: why can’t everyone agree on a standardized set of names? Huntley acknowledges that this is a complex issue, as each company interprets data through its specific lens, resulting in divergent views of the same group. He stated, "No one has perfect visibility. We’re constructing our model, but we can never have a complete understanding of every activity." By harmonizing the naming conventions of Google's Threat Analysis Group and Mandiant, Google aims to simplify the landscape, creating a more unified approach for cybersecurity professionals to reference. For those seeking a comprehensive overview, an extensive list is available for consultation.
On Wednesday, Stripe officially announced its acquisition of OpenRouter, a significant move in the tech space. Although ...
TechCrunch | Aug 20, 2026, 24:05
Travis Kalanick, the co-founder of Uber, has always had a tumultuous relationship with venture capitalists (VCs). Initia...
TechCrunch | Aug 19, 2026, 22:35
A groundbreaking device designed to target and eliminate mosquitoes while they fly is transitioning from the prototype p...
Business Today | Aug 20, 2026, 04:45
In a recent update, Samsung has announced a price increase for its Galaxy S25 smartphone models in India, affecting both...
Business Today | Aug 20, 2026, 05:15
Rillet, an innovative AI accounting startup, has successfully raised $100 million in its Series C funding round, reachin...
TechCrunch | Aug 19, 2026, 20:30