Google has revised its methodology for identifying hacking groups. The previous system, which used numerical APT designations like APT1 or APT41, has been replaced. This older system was initially adopted by Mandiant, a security firm now part of Google.
The updated naming convention assigns a memorable, random first word to each hacking group. The second word's initial letter indicates the group's country of origin. For instance, 'Castle' denotes China, 'Ion' signifies Iran, 'Neptune' represents North Korea, and 'Relic' points to Russia.
Shane Huntley, CTO of Google Threat Intelligence Group, stated that the revamp was necessary to enhance clarity for both internal and external security researchers. The cybersecurity industry now tracks over 5,000 'activity clusters,' a significant increase from the early 2010s when naming systems were first established. This proliferation of groups made the previous tracking methods difficult to manage.
Naming and consistently tracking hacking groups provides a baseline understanding of who is conducting cyberattacks and their methods. This information allows organizations to recognize threats more quickly, prepare defenses, and investigate incidents more promptly. Consistent identification is crucial for effective cybersecurity responses.
✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →
One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.
One email a day. Unsubscribe in one click, any time.
Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.
▶ Play today's briefNew every morning, and the back catalogue is archived by date.
Google has updated its system for naming hacking groups, moving away from numerical APT designations to a new two-word format that includes a country-of-origin indicator. This change aims to improve clarity and consistency for security researchers tracking the increasing number of threat actors.