← All stories
● Covered by 1 source · 1 reportMedium impact1 neutral

Google Threat Intelligence Group Unifies Threat Actor Naming System

🔄 Updated 1h ago
New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • GTIG unifies Mandiant and TAG threat actor naming.
  • New system uses two-word cryptonyms for clarity.
  • First word identifies actor, second categorizes by motivation/activity.
  • Prioritizes renaming active groups, with ongoing rollout.

Unified Naming System Introduced

The Google Threat Intelligence Group (GTIG) has launched a new, unified naming system for identifying and tracking threat actors. This initiative merges the previously distinct tracking methodologies employed by Mandiant and Google's Threat Analysis Group (TAG), which had developed independently over time. The consolidation into GTIG necessitated a single, coherent system.

Rationale for the Change

The previous reliance on sequential numbers or disparate identifiers, such as "APT1," often lacked critical context for defenders. The new cryptonym-based system is designed to be more intuitive and memorable, aligning with industry standards for threat actor naming. This approach aims to simplify the process of understanding and responding to threat intelligence.

Structure of the New Schema

The new naming convention uses two-word combinations. The first word is a unique and memorable term, often derived from prior public reporting or randomly generated to avoid bias. The second word categorizes threat clusters based on their motivation, attribution, or activity type, providing immediate context for defense and response strategies. This structure is intended to streamline operations and facilitate mapping to other industry taxonomies.

Implementation and Future Plans

GTIG has begun by renaming several dozen of the most active threat groups and plans to continue this process on a rolling basis. While acknowledging that direct comparisons between threat actors across different organizations are challenging due to varying visibility, the new system is presented as a practical step towards managing the complexities of threat tracking. Previous names will remain indexed for reference.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~15 min · 15 stories · Jul 24

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

Reporting from

Google Threat Intelligence Group (GTIG) has introduced a new unified naming schema for tracking threat actors, replacing the previously separate systems used by Mandiant and Google's Threat Analysis Group (TAG). This change aims to standardize threat actor identification across platforms and public reporting, making it easier for defenders to understand and respond to threats.