Saturday, 8 August 2026
Rīga TV

World and Latvian news in one place

TechnologyPublished: 8 August 2026 at 18:16

Google's top hacker hunter explains the logic behind hacking group codenames

Google overhauled its naming system for hacking groups last month, replacing Mandiant's old APT numbering with memorable codenames. A company executive explains why consistent naming helps defenders track and respond to cyber threats.

Foto: TechCrunch

Last month Google revamped how it names hacking groups, becoming the latest company to update its system for tracking cyber threat actors. Gone are designations like APT1 or APT41, first introduced by Mandiant, the security firm that is now part of Google.

Under the new system, each group gets a memorable first name, paired with a second word whose initial letter signals the country of origin: Castle for China, Ion for Iran, Neptune for North Korea, and Relic for Russia.

Why clarity matters

Shane Huntley, chief technology officer of Google Threat Intelligence Group, said the overhaul was needed to give researchers inside and outside the company a clearer picture. When companies began publishing reports on cyberattacks and naming their perpetrators in the early 2010s, nobody expected the number of tracked threat groups to grow as large as it has. According to John Hultquist, chief analyst at Google Threat Intelligence Group, the company now tracks more than 5,000 activity clusters across multiple countries.

Huntley noted that few developed nations today lack their own cyber capabilities and hacking groups. Naming these groups isn't just an academic exercise — it gives organizations a baseline for recognizing threats faster, preparing defenses, and responding to incidents more quickly. Knowing how a group like North Korea's Lazarus Group typically behaves gives defenders a starting point for handling an incident involving them.

Tracking state-sponsored hackers is generally easier than tracking cybercriminal groups, Huntley explained, since criminal groups tend to be more fluid, with members joining, leaving, and splintering off. Asked why companies don't simply adopt a single shared naming system, Huntley said each organization has its own data and visibility into every group, making full unification unrealistic — no one has a complete picture. Still, by merging the naming schemes of its former Threat Analysis Group and Mandiant, Google has at least reduced the number of systems the industry needs to keep track of.

Comments

0/1500

Comments are automatically moderated. No hate, threats, personal data or spam.

Loading comments…

More in this category