Key facts
- Google has adopted a new naming system for hacking groups, featuring memorable first names and country-indicating second words (e.g., Castle for China, Ion for Iran).
- Shane Huntley, CTO of Google Threat Intelligence Group, stated the revamp is necessary for clarity among security researchers.
- The goal of naming hacking groups is to understand who is attacking whom and how, aiding in threat recognition and incident response.
- Google currently tracks over 5,000 'activity clusters' globally.
- Huntley noted that state-sponsored hackers are typically easier to track than cybercriminal groups due to more consistent targets and activities.
The cybersecurity industry has long assigned codenames to hacking groups, a practice that has become increasingly complex due to the sheer volume of actors and differing naming conventions across companies. Google, through its Threat Intelligence Group, has recently updated its own system to address this challenge.
Previously, Mandiant, now part of Google, used a numerical system like APT1 or APT41. The new Google system simplifies this by assigning a memorable, random first name and a second word whose initial denotes the country of origin. Examples include 'Castle' for China, 'Ion' for Iran, 'Neptune' for North Korea, and 'Relic' for Russia.
