The Google Threat Intelligence Group (GTIG) has launched a new, unified naming system for identifying and tracking threat actors. This initiative merges the previously distinct tracking methodologies employed by Mandiant and Google's Threat Analysis Group (TAG), which had developed independently over time. The consolidation into GTIG necessitated a single, coherent system.
The previous reliance on sequential numbers or disparate identifiers, such as "APT1," often lacked critical context for defenders. The new cryptonym-based system is designed to be more intuitive and memorable, aligning with industry standards for threat actor naming. This approach aims to simplify the process of understanding and responding to threat intelligence.
The new naming convention uses two-word combinations. The first word is a unique and memorable term, often derived from prior public reporting or randomly generated to avoid bias. The second word categorizes threat clusters based on their motivation, attribution, or activity type, providing immediate context for defense and response strategies. This structure is intended to streamline operations and facilitate mapping to other industry taxonomies.
GTIG has begun by renaming several dozen of the most active threat groups and plans to continue this process on a rolling basis. While acknowledging that direct comparisons between threat actors across different organizations are challenging due to varying visibility, the new system is presented as a practical step towards managing the complexities of threat tracking. Previous names will remain indexed for reference.
✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →
One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.
One email a day. Unsubscribe in one click, any time.
Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.
▶ Play today's briefNew every morning, and the back catalogue is archived by date.
Google Threat Intelligence Group (GTIG) has introduced a new unified naming schema for tracking threat actors, replacing the previously separate systems used by Mandiant and Google's Threat Analysis Group (TAG). This change aims to standardize threat actor identification across platforms and public reporting, making it easier for defenders to understand and respond to threats.