Google Unifies Cyber Threat Actor Naming With New Cryptonym-Based System to Simplify Global Threat Tracking
Google Threat Intelligence Group has introduced a unified cyber threat actor naming system, replacing separate tracking across Google and Mandiant. The new cryptonym-based taxonomy simplifies threat intelligence, improves incident response, and enhances defender collaboration.
Xcademia Team
Xcademia Research Team

Google Introduces Unified Threat Actor Naming System to Simplify Cyber Threat Intelligence
Cyber threat intelligence has become increasingly complex as security teams track thousands of threat actors operating across different regions, industries, and attack campaigns. While organisations depend on accurate attribution to understand adversaries, one longstanding challenge has remained consistent: different security vendors often assign different names to the same threat actor.
To address this issue, Google Threat Intelligence Group (GTIG) has announced a new unified threat actor naming schema that introduces memorable cryptonym-based identifiers for cyber adversaries. The initiative aims to simplify threat tracking, improve intelligence sharing, and accelerate defensive operations across the cybersecurity ecosystem.
The announcement marks one of Google's most significant updates to threat intelligence since the integration of Mandiant and Google's Threat Analysis Group (TAG) into GTIG.
Why Threat Actor Naming Has Become Increasingly Complex
Over the years, multiple cybersecurity vendors have independently tracked nation-state groups, ransomware operators, financially motivated attackers, and emerging cyber campaigns.
As each organisation developed its own research methodology, separate naming conventions naturally emerged.
Examples include:
APT-style numbering
Vendor-specific code names
Internal tracking identifiers
Temporary investigation labels
Campaign-specific aliases
Although these systems serve internal research well, they often create confusion for defenders attempting to correlate intelligence from multiple sources.
For example, one advanced persistent threat may simultaneously be known under several completely different names depending on the security vendor publishing the report.
This fragmentation increases the workload for:
Security Operations Centres (SOC)
Incident response teams
Threat intelligence analysts
Government agencies
Enterprise security teams
Instead of focusing on analysing attacker behaviour, analysts frequently spend valuable time determining whether different reports are describing the same adversary.
The Evolution of Google Threat Intelligence
Google's current threat intelligence capabilities combine expertise from several major security organisations.
These include:
Google Threat Analysis Group (TAG)
Mandiant Intelligence
Google Cloud Security
Google Threat Intelligence platform
Historically, both Mandiant and TAG maintained separate tracking systems that evolved independently over many years.
Following their integration into Google Threat Intelligence Group, maintaining parallel naming systems became increasingly inefficient.
Rather than continuing multiple overlapping taxonomies, Google decided to create a single framework that supports consistent tracking across products, intelligence reports, investigations, and customer platforms.
Introducing Google's Cryptonym-Based Naming System
Instead of relying on sequential numbers such as APT1 or unrelated internal identifiers, Google has adopted a two-word cryptonym structure.
Each threat actor will receive a unique identifier composed of two meaningful words.
First Word: Unique Actor Identifier
The first element uniquely identifies an individual threat actor.
Whenever possible, Google will reuse familiar public terminology already associated with a group.
If no widely recognised name exists, analysts generate a new memorable term through a controlled random process before validating it internally.
This approach helps reduce naming bias while ensuring consistency across future investigations.
Second Word: Threat Category
The second word identifies the broader category of the threat actor.
Rather than indicating technical capability, it represents the motivation, origin, or attribution considered most useful for defenders.
Current category examples include:
Threat Type | Cryptonym Category |
|---|---|
People's Republic of China | CASTLE |
Iran | ION |
North Korea | NEPTUNE |
Russia | RELIC |
Cybercriminal | COMET |
The resulting combinations are intended to be easier to recognise, remember, and communicate during incident response activities.

Why Memorable Names Improve Defensive Operations
One of Google's primary objectives is making threat intelligence more intuitive.
Traditional numbering systems require analysts to memorise hundreds of identifiers without providing meaningful context.
Cryptonym-based naming improves operational efficiency by allowing analysts to immediately recognise:
Threat motivation
Geographic attribution
Campaign relationships
Intelligence correlations
Defensive priorities
Rather than memorising arbitrary numbers, defenders can associate meaningful categories with specific adversaries.
This reduces cognitive overhead during high-pressure investigations where response speed is essential.
Mapping Existing Intelligence Without Losing Historical Context
Changing naming conventions presents a challenge because security teams have accumulated years of historical intelligence.
Google addresses this by preserving existing references inside the Google Threat Intelligence (GTI) platform.
The platform will continue supporting:
Previous Mandiant names
Legacy Google TAG identifiers
MITRE ATT&CK mappings
Vendor aliases
Historical reports
Existing threat intelligence records
This ensures analysts can transition gradually without losing valuable historical context.
Searches for legacy names will continue returning the appropriate threat actor profiles.
UNC Designations Continue for Emerging Threats
Not every cyber threat immediately receives a permanent classification.
Google will continue using UNC (Uncategorised) identifiers for newly discovered threat clusters that remain under investigation.
These temporary designations allow analysts to:
Track emerging campaigns
Correlate new intelligence
Gather attribution evidence
Monitor evolving infrastructure
Observe behavioural patterns
Once sufficient evidence exists, those clusters may eventually receive permanent cryptonym assignments.
This staged approach maintains analytical accuracy while avoiding premature attribution.

Benefits for Security Teams and the Wider Industry
Google's initiative extends beyond simplifying internal operations.
A consistent naming framework offers several broader advantages for the cybersecurity community.
Faster Threat Correlation
Analysts can more quickly determine whether separate reports describe the same threat actor.
Improved Intelligence Sharing
Security vendors, governments, and enterprises can communicate with fewer translation errors.
Better Incident Response
Clearer naming reduces confusion during active investigations where every minute matters.
Simplified Training
New analysts spend less time memorising complex numbering systems and more time understanding attacker behaviour.
Enhanced Automation
Security platforms can more easily map aliases, enrich alerts, and automate threat intelligence correlation.
Industry Challenges Still Remain
Google acknowledges that no universal naming system can fully eliminate attribution challenges.
Different organisations possess different:
Telemetry
Customer visibility
Malware samples
Investigation timelines
Intelligence sources
As a result, one vendor's understanding of a threat actor may differ from another's.
Direct one-to-one comparisons between vendor naming systems will continue requiring careful correlation.
Google's objective is not to replace every industry taxonomy but to make its own intelligence easier to understand and integrate with existing frameworks.
Implications for the Future of Cyber Threat Intelligence
The announcement reflects a broader shift toward improving operational usability rather than simply collecting more intelligence.
Modern security operations increasingly rely on:
AI-assisted threat analysis
Automated correlation
Large-scale intelligence platforms
Cross-vendor data integration
Shared defensive ecosystems
Clear and consistent naming becomes increasingly important as machine learning systems consume structured threat intelligence at scale.
A simplified taxonomy also supports faster collaboration between enterprises, cloud providers, government agencies, and security vendors.
As cyber threats continue growing in sophistication, reducing friction in information sharing may become just as valuable as discovering new indicators of compromise.

Looking Ahead
Google has begun the rollout by renaming several dozen of the most active threat groups and plans to expand the system over time.
As additional threat actors receive new cryptonyms, the Google Threat Intelligence platform will continue maintaining historical aliases, ATT&CK mappings, and previous identifiers to support smooth adoption.
Although no naming convention can completely eliminate the complexity of cyber attribution, Google's approach represents an important step towards making threat intelligence more intuitive, searchable, and actionable.
For enterprise defenders, clearer naming means less time decoding vendor terminology and more time identifying, understanding, and responding to real-world cyber threats.
As the cybersecurity landscape continues evolving, initiatives that improve clarity and interoperability may become just as critical as advances in detection technology itself.
About the Author