As cited
Citation snapshot as of .
threat intel
Google’s solution to hacker name confusion? Yet another naming system
Google Threat Intelligence Group has unified its hacker naming system by merging Mandiant and in-house naming conventions into a two-word format, with the first word as a memorable identifier and the second word denoting category such as country of origin or motive. The new taxonomy follows a structure similar to CrowdStrike's animal-based system and Microsoft's weather-based system, and Google is collaborating with other vendors on mappings to reduce industry-wide confusion. Legacy names remain searchable within Google's platform with cross-references to other vendor systems.
Why it matters: Security teams tracking the same threat actors across tools from Google, Microsoft, and CrowdStrike now have a coordinated mapping effort to reduce operational friction from competing naming conventions; the rollout starts with major groups and legacy names stay accessible for continuity.
- Source published
- First seen by Cybersecurity Tracker