CYBERSECURITYTRACKER
TRACKING3,967 stories737 vuln stories
Permanent story citation

Google’s solution to hacker name confusion? Yet another naming system

The story is preserved as cited. Later corrections remain visibly typed and adjacent to the original snapshot.

← newsStory 3286

As cited

Citation snapshot as of .

threat intel

Google’s solution to hacker name confusion? Yet another naming system

Google Threat Intelligence Group has unified its hacker naming system by merging Mandiant and in-house naming conventions into a two-word format, with the first word as a memorable identifier and the second word denoting category such as country of origin or motive. The new taxonomy follows a structure similar to CrowdStrike's animal-based system and Microsoft's weather-based system, and Google is collaborating with other vendors on mappings to reduce industry-wide confusion. Legacy names remain searchable within Google's platform with cross-references to other vendor systems.

Why it matters: Security teams tracking the same threat actors across tools from Google, Microsoft, and CrowdStrike now have a coordinated mapping effort to reduce operational friction from competing naming conventions; the rollout starts with major groups and legacy names stay accessible for continuity.

Source published
First seen by Cybersecurity Tracker

Source attribution