Google adds to confusion with new names for threat actors

Tags:

Google is creating a new naming scheme for the bad actors behind cybersecurity threats, hoping that it will help to standardize the way that attacks are reported. Spoiler: It won’t.

Security researchers use these naming schemes so that they can attribute attacks without necessarily knowing exactly who is behind them. Google had naming schemes in use internally: one developed by its own Threat Analysis Group (TAG), and one developed by Mandiant, now a Google subsidiary.  

Now they will both use a new naming scheme developed by Google Threat Intelligence Group (GTIG replacing the previous systems based on sequential numbers or vague identifiers.

The new method of naming will involve a two-word approach: The first word will refer to motivation, attribution, or activity type, while the second word will represent the specific threat actor, for example, threats from China will end with “CASTLE,” while those from Russia will end with “RELIC.” If a threat group is not believed to be state-sponsored, then the last word will be “COMET.”

Google has already created new names for existing threat groups: TEMP.Tick is now TICK CASTLE, while FIN11 is now RAZOR COMET.

Rather than coming up with a whole new naming scheme, Google could have just standardized on one of its two internal systems. Or adopt the one Microsoft created in 2023. Or continue to work with industry attempts to create a common taxonomy as it said it would do in 2025.

It’s all rather reminiscent of the situation Randall Munroe lampooned in his XKCD comic strip, “How standards proliferate.”

Categories

No Responses

Leave a Reply

Your email address will not be published. Required fields are marked *