All NewsEducationTV
Equities & FundsCrypto & Digital AssetsAI & TechnologyBusiness & CorporateUS Politics & PolicyGeopolitics & Global RiskMacro, Rates & FXCommodities & EnergyEuropean Politics & MarketsAsia-PacificReal Estate & Property
Story archiveAll categories
← All Stories

Google's hacker naming system explained by Shane Huntley

Created at 8 Aug · 3:15 PM1 source↑ Market-relevant
IN SHORT

Google has updated its hacking group naming system to include memorable first names and country-indicating second words, aiming to bring clarity to cybersecurity researchers. Shane Huntley, CTO of Google Threat Intelligence Group, explained the necessity of consistent naming for threat recognition and incident response.

✉Newsletter

PiQ Daily

Pick your topics. Get only what matters, on your cadence.

Key Numbers

5,000activity clusters tracked by Google

Who's Involved

Shane Huntley
CTO of Google Threat Intelligence Group
John Hultquist
Chief Analyst at Google Threat Intelligence Group
Google's hacker naming system explained by Shane Huntley

↳ Why This Matters

Consistent and clear naming of hacking groups is essential for effective cybersecurity, enabling organizations to better understand, track, and defend against evolving cyber threats from various state-sponsored and criminal actors.

Key facts

  • Google has adopted a new naming system for hacking groups, featuring memorable first names and country-indicating second words (e.g., Castle for China, Ion for Iran).
  • Shane Huntley, CTO of Google Threat Intelligence Group, stated the revamp is necessary for clarity among security researchers.
  • The goal of naming hacking groups is to understand who is attacking whom and how, aiding in threat recognition and incident response.
  • Google currently tracks over 5,000 'activity clusters' globally.
  • Huntley noted that state-sponsored hackers are typically easier to track than cybercriminal groups due to more consistent targets and activities.

The cybersecurity industry has long assigned codenames to hacking groups, a practice that has become increasingly complex due to the sheer volume of actors and differing naming conventions across companies. Google, through its Threat Intelligence Group, has recently updated its own system to address this challenge.

Previously, Mandiant, now part of Google, used a numerical system like APT1 or APT41. The new Google system simplifies this by assigning a memorable, random first name and a second word whose initial denotes the country of origin. Examples include 'Castle' for China, 'Ion' for Iran, 'Neptune' for North Korea, and 'Relic' for Russia.

Shane Huntley, CTO of Google Threat Intelligence Group, explained that the revamp is crucial for providing clarity to both internal and external security researchers. He noted that in the early 2010s, when naming began, the number of threat groups was not anticipated to be as large as it is today. Google now tracks over 5,000 'activity clusters' across various countries, highlighting the widespread nature of cyber capabilities.

Huntley emphasized that naming hacking groups is not merely an academic exercise. It serves to establish a baseline understanding of attacker motivations and methods, enabling organizations to recognize threats more quickly, prepare defenses, and investigate incidents more efficiently. Knowing an actor's behavior, past actions, and affiliations, such as those of the North Korean Lazarus Group, is critical for effective incident response and threat mitigation.

He further elaborated that tracking state-sponsored hackers is generally more manageable than tracking cybercriminal or hacker-for-hire groups, which tend to be more amorphous with members frequently joining and leaving. The diverse customer base of hacker-for-hire entities also complicates tracking.

A common criticism is the lack of a universal naming system. Huntley acknowledged that this is an inescapable reality, as each company's perspective on a group is shaped by its unique data and telemetry, and no single entity possesses perfect visibility. By unifying the naming schemes of Google's former Threat Analysis Group and Mandiant, Google aims to reduce the number of systems researchers need to track.

Frequently asked questions

Google's new system assigns a memorable, random first name and a second word whose initial indicates the country of origin, such as 'Castle' for China or 'Relic' for Russia.

The revamp was necessary to bring clarity to security researchers, as the number of threat groups has grown significantly, making it difficult to keep track.

Naming helps organizations understand who is attacking them, how they are attacking, which aids in recognizing threats, preparing defenses, and investigating incidents more promptly.

Yes, according to Shane Huntley, state-sponsored hackers tend to have more consistent targets and activities, making them easier to track than cybercriminal groups.

What Happens Next

01Google will continue to track and name hacking groups under its new system.

Get the newsletter.

Pick the topics you actually care about. We'll email when there's news worth your time, on the cadence you choose. Cancel any time from your account.

Cadence

How It Developed

The cybersecurity industry has assigned codenames to hacking groups for over a decade.
Google revamped its hacking group naming system last month.
The new system uses memorable first names and country-indicating second words.
Shane Huntley explained the revamp aims to bring clarity to security researchers.
Google tracks over 5,000 'activity clusters' globally.
Naming hacking groups helps organizations recognize and prepare for threats.
State-sponsored hackers are generally easier to track than cybercriminals.
Companies use different naming systems due to varying data and visibility.

Sources

T1
Google’s top hacker hunter explains why hacking groups get codenamesTechCrunch

Related Stories

OpenAI Pauses Astra Model Development Over Cybersecurity Concerns
7 Aug · 11:25 PM
Polish web infrastructure at risk of hacks, researchers find
7 Aug · 9:21 PM
Demis Hassabis steps down as Google DeepMind CEO to become chief scientist
8 Aug · 12:11 PM
Replit CEO: AI is making software engineering more cerebral and fun
8 Aug · 9:36 AM
China's AI Development Faces Data Shortage
8 Aug · 2:06 AM