{"id":8957,"date":"2026-07-31T13:52:22","date_gmt":"2026-07-31T13:52:22","guid":{"rendered":"https:\/\/cybersecurityinfocus.com\/?p=8957"},"modified":"2026-07-31T13:52:22","modified_gmt":"2026-07-31T13:52:22","slug":"google-adds-to-confusion-with-new-names-for-threat-actors","status":"publish","type":"post","link":"https:\/\/cybersecurityinfocus.com\/?p=8957","title":{"rendered":"Google adds to confusion with new names for threat actors"},"content":{"rendered":"<div>\n<div class=\"grid grid--cols-10@md grid--cols-8@lg article-column\">\n<div class=\"col-12 col-10@md col-6@lg col-start-3@lg\">\n<div class=\"article-column__content\">\n<div class=\"container\"><\/div>\n<p class=\"wp-block-paragraph\">Google is creating a new naming scheme for the bad actors behind cybersecurity threats, hoping that it will help to standardize the way that attacks are reported. Spoiler: It won\u2019t.<\/p>\n<p class=\"wp-block-paragraph\">Security researchers use these naming schemes so that they can attribute attacks without necessarily knowing exactly who is behind them. Google had naming schemes in use internally: one developed by its own Threat Analysis Group (TAG), and one developed by Mandiant, now a Google subsidiary. \u00a0<\/p>\n<p class=\"wp-block-paragraph\">Now they will both use a <a href=\"https:\/\/cloud.google.com\/blog\/topics\/threat-intelligence\/updated-cyber-threat-actor-naming-system\/\" target=\"_blank\" rel=\"noopener\">new naming scheme developed by Google Threat Intelligence Group<\/a> (GTIG replacing the previous systems based on sequential numbers or vague identifiers.<\/p>\n<p class=\"wp-block-paragraph\">The new method of naming will involve a two-word approach: The first word will refer to motivation, attribution, or activity type, while the second word will represent the specific threat actor, for example, threats from China will end with \u201cCASTLE,\u201d while those from Russia will end with \u201cRELIC.\u201d If a threat group is not believed to be state-sponsored, then the last word will be \u201cCOMET.\u201d<\/p>\n<p class=\"wp-block-paragraph\">Google has already created new names for existing threat groups: TEMP.Tick is now TICK CASTLE, while FIN11 is now RAZOR COMET.<\/p>\n<p class=\"wp-block-paragraph\">Rather than coming up with a whole new naming scheme, Google could have just standardized on one of its two internal systems. Or adopt the one <a href=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\/2023\/04\/18\/microsoft-shifts-to-a-new-threat-actor-naming-taxonomy\/\" target=\"_blank\" rel=\"noopener\">Microsoft created in 2023<\/a>. Or continue to work with <a href=\"https:\/\/www.csoonline.com\/article\/4000860\/one-hacker-many-names-industry-collaboration-aims-to-fix-cyber-threat-label-chaos.html\">industry attempts to create a common taxonomy<\/a> as it said it would do in 2025.<\/p>\n<p class=\"wp-block-paragraph\">It\u2019s all rather reminiscent of the situation Randall Munroe lampooned in his XKCD comic strip, \u201c<a href=\"https:\/\/xkcd.com\/927\/\" target=\"_blank\" rel=\"noopener\">How standards proliferate<\/a>.\u201d<\/p>\n<p class=\"wp-block-paragraph\">\n<\/p><\/div>\n<\/div>\n<\/div>\n<\/div>","protected":false},"excerpt":{"rendered":"<p>Google is creating a new naming scheme for the bad actors behind cybersecurity threats, hoping that it will help to standardize the way that attacks are reported. Spoiler: It won\u2019t. Security researchers use these naming schemes so that they can attribute attacks without necessarily knowing exactly who is behind them. Google had naming schemes in [&hellip;]<\/p>\n","protected":false},"author":0,"featured_media":8958,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[3],"tags":[],"class_list":["post-8957","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-education"],"_links":{"self":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/posts\/8957"}],"collection":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"replies":[{"embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=8957"}],"version-history":[{"count":0,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/posts\/8957\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/media\/8958"}],"wp:attachment":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=8957"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=8957"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=8957"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}