← All stories
● Covered by 1 source · 1 reportMedium impact1 neutral

Google revamps its hacking group naming system for clarity and consistency

🔄 Updated 1d ago
New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • Google replaced its APT naming system for hacking groups.
  • New system uses a random first name and a second word indicating country of origin.
  • Examples: Castle for China, Ion for Iran, Neptune for North Korea, Relic for Russia.
  • The change aims to bring clarity to security researchers tracking over 5,000 groups.

New Naming Convention Introduced

Google has revised its methodology for identifying hacking groups. The previous system, which used numerical APT designations like APT1 or APT41, has been replaced. This older system was initially adopted by Mandiant, a security firm now part of Google.

Structure of the New System

The updated naming convention assigns a memorable, random first word to each hacking group. The second word's initial letter indicates the group's country of origin. For instance, 'Castle' denotes China, 'Ion' signifies Iran, 'Neptune' represents North Korea, and 'Relic' points to Russia.

Rationale Behind the Change

Shane Huntley, CTO of Google Threat Intelligence Group, stated that the revamp was necessary to enhance clarity for both internal and external security researchers. The cybersecurity industry now tracks over 5,000 'activity clusters,' a significant increase from the early 2010s when naming systems were first established. This proliferation of groups made the previous tracking methods difficult to manage.

Importance of Naming Hacking Groups

Naming and consistently tracking hacking groups provides a baseline understanding of who is conducting cyberattacks and their methods. This information allows organizations to recognize threats more quickly, prepare defenses, and investigate incidents more promptly. Consistent identification is crucial for effective cybersecurity responses.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~7 min · 6 stories · Aug 15

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

Reporting from

Google has updated its system for naming hacking groups, moving away from numerical APT designations to a new two-word format that includes a country-of-origin indicator. This change aims to improve clarity and consistency for security researchers tracking the increasing number of threat actors.