Google is giving cyber threats a whole new identity. Here's how its new naming system could make online security easier to understand.

Cybersecurity can be confusing, especially when the same hacking group is known by several different names. That's exactly the problem the Google naming system aims to solve. Google Threat Intelligence Group (GTIG) has introduced a new way to identify cyber threat actors, making it easier for security teams, businesses, and researchers to understand who they are dealing with.

One Name, Less Confusion

For years, Google's Threat Analysis Group (TAG) and Mandiant tracked cyber threat actors using separate naming systems. After both teams came together under GTIG, having two different approaches created unnecessary confusion.

Now, Google is replacing those older labels with memorable two-word cryptonyms. The first word gives each threat actor a unique identity, while the second word explains the group's broader category, such as its origin or motivation.

For example, threat actors linked to Russia will use RELIC, China-linked groups will use CASTLE, Iran-linked actors will use ION, North Korea-linked groups will use NEPTUNE, and cybercriminal organizations will use COMET.

Why Does This Change Matter?

Instead of forcing analysts to remember complex labels like APT44 or dozens of different aliases, the new naming system provides useful context at a glance.

As Google explained, "Threat tracking shouldn't be an exercise in memorization, but rather one of intuition." That simple idea is driving the company's effort to make cyber intelligence easier to understand and faster to use.

The change also aligns Google's naming approach with industry practices while making collaboration across security teams much smoother.

Will Older Threat Names Disappear?

Google says previous names will remain searchable inside its Google Threat Intelligence platform. MITRE ATT&CK mappings and aliases from other cybersecurity vendors will also stay available, helping analysts connect older reports with the new naming convention. The company is also keeping its UNC label for suspicious threat clusters that are still under investigation and haven't yet been fully classified.

Can One Naming System Fix Cybersecurity?

Different cybersecurity organizations often have different levels of visibility into attacks, meaning the same threat actor may still receive different names elsewhere. Google acknowledges that no naming system can completely eliminate attribution challenges. Instead, the new taxonomy focuses on making threat intelligence clearer, faster, and easier to understand without losing historical context.

What Happens Next?

Google is rolling out the new naming system gradually, starting with several dozen of the most active threat groups. More actors will receive updated cryptonyms over time as the rollout expands.

As cyber threats continue to evolve, Business Fortune believes that a simpler and more consistent naming approach could help security teams respond more quickly, improve collaboration across the industry, and make cyber intelligence easier for everyone to follow.

 

FAQ

What is Google's new naming system?

It is a unified naming method that gives every cyber threat actor a memorable two-word cryptonym to make identification easier.

Why did Google introduce this system?

Google wanted to eliminate confusion caused by multiple naming systems used by different security teams and improve threat tracking.

Will old threat actor names still be available?

Yes. Previous names, MITRE ATT&CK mappings, and vendor aliases will remain searchable during the transition.

What do words like RELIC and COMET mean?

They represent broad categories. For example, RELIC refers to Russia-linked actors, while COMET identifies cybercriminal groups.

Will this become the global cybersecurity standard?

Not necessarily. Other security companies may continue using their own naming systems, but Google's approach is designed to make cross-platform tracking simpler.