As cited
Copy frozen at (site build).
threat intel
Updated Cyber Threat Actor Naming System
Google Threat Intelligence Group is launching a new cryptonym-based naming system for tracking threat actors, replacing the separate schemas previously maintained by Mandiant and Google's Threat Analysis Group. The system uses memorable two-word combinations where the first word identifies the actor and the second word indicates its origin, type, or motivation, with categories assigned to countries and cybercriminal groups. Google will rename several dozen active groups initially and continue on a rolling basis, preserving legacy names and mappings for cross-reference.
Why it matters: Defenders relying on Google's threat intelligence or coordinating across teams using different naming schemes will need to adopt the new cryptonym system to maintain consistency in incident response and threat tracking discussions.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
threat intel
Updated Cyber Threat Actor Naming System
Google Threat Intelligence Group is launching a new cryptonym-based naming system for tracking threat actors, replacing the separate schemas previously maintained by Mandiant and Google's Threat Analysis Group. The system uses memorable two-word combinations where the first word identifies the actor and the second word indicates its origin, type, or motivation, with categories assigned to countries and cybercriminal groups. Google will rename several dozen active groups initially and continue on a rolling basis, preserving legacy names and mappings for cross-reference.
Why it matters: Defenders relying on Google's threat intelligence or coordinating across teams using different naming schemes will need to adopt the new cryptonym system to maintain consistency in incident response and threat tracking discussions.
- Source published
- First seen by Cybersecurity Tracker