CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

Updated Cyber Threat Actor Naming System

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 3186

As cited

Copy frozen at (site build).

threat intel

Updated Cyber Threat Actor Naming System

Google Threat Intelligence Group is launching a new cryptonym-based naming system for tracking threat actors, replacing the separate schemas previously maintained by Mandiant and Google's Threat Analysis Group. The system uses memorable two-word combinations where the first word identifies the actor and the second word indicates its origin, type, or motivation, with categories assigned to countries and cybercriminal groups. Google will rename several dozen active groups initially and continue on a rolling basis, preserving legacy names and mappings for cross-reference.

Why it matters: Defenders relying on Google's threat intelligence or coordinating across teams using different naming schemes will need to adopt the new cryptonym system to maintain consistency in incident response and threat tracking discussions.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

Updated Cyber Threat Actor Naming System

Google Threat Intelligence Group is launching a new cryptonym-based naming system for tracking threat actors, replacing the separate schemas previously maintained by Mandiant and Google's Threat Analysis Group. The system uses memorable two-word combinations where the first word identifies the actor and the second word indicates its origin, type, or motivation, with categories assigned to countries and cybercriminal groups. Google will rename several dozen active groups initially and continue on a rolling basis, preserving legacy names and mappings for cross-reference.

Why it matters: Defenders relying on Google's threat intelligence or coordinating across teams using different naming schemes will need to adopt the new cryptonym system to maintain consistency in incident response and threat tracking discussions.

VendorsGoogle
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary