Google Overhauls Hacking Group Naming System to Bring Clarity to Threat Tracking

Google revamped its naming system for hacking groups in July 2026, replacing the long-running numbered APT scheme with a new format designed to be more intuitive for security researchers inside and outside the company.

Under the new system, each hacking group receives a two-word name: a random, memorable first name paired with a second word whose initial letter indicates the group’s country of origin. The designations are Castle for China, Ion for Iran, Neptune for North Korea, and Relic for Russia. The change consolidates the naming conventions previously used separately by Google’s Threat Analysis Group and Mandiant, the security firm now part of Google that originally introduced the APT numbering scheme.

Shane Huntley, chief technology officer of Google Threat Intelligence Group, told TechCrunch the overhaul was needed because the old system had become difficult to navigate. Google now tracks more than 5,000 “activity clusters” across multiple countries, according to John Hultquist, chief analyst at the same group. Huntley noted that very few developed nations lack their own cyber capabilities and hacking groups.

Naming groups is not purely academic, Huntley explained. Consistent tracking allows organizations to recognize threats faster, prepare defenses, and respond to incidents more effectively. “If you actually get hacked by them or you’re dealing with some incident, knowing how that actor behaves, what they do, what they’ve done in the past, all of these details become critically important,” he said.

Huntley acknowledged a persistent industry challenge: every security company names groups differently because each works from its own data and telemetry. He said that sharing more information among researchers cannot fully resolve those differences. “No one has perfect visibility,” he said. “We will never know everything about what’s going on.”

The consolidation means one fewer naming scheme for the industry to track, though a wide range of competing systems from other organizations remains in use.

Source: TechCrunch

This article was generated by AI and cites original sources.
Scroll to Top