Why Google Renamed 5,000+ Hacking Groups — And Why Cybersecurity Professionals Should Care

Google's new naming system for threat actors signals a maturity in how the industry tracks, classifies, and communicates about state-sponsored and criminal hacking groups

Why Google Renamed 5,000+ Hacking Groups — And Why Cybersecurity Professionals Should Care

Google's New Naming System Changes How We Track Cyber Threats

For developers, IT decision-makers, and security professionals navigating an increasingly hostile digital landscape, hacking group tracking cybersecurity has always been a messy business. Too many names, too many vendors with conflicting taxonomies, and too little clarity about who is actually behind a breach. Google has now stepped in with a significant overhaul of how it identifies and communicates about threat actors — a move with real implications for enterprise security teams, policymakers, and anyone building digital infrastructure in today's geopolitical environment.

Google's Threat Intelligence Group has retired its legacy APT (Advanced Persistent Threat) numbering system — the string of designations like APT1, APT41, and so on that Mandiant originally pioneered when it was an independent security firm — in favour of a more intuitive, memorable, and unified naming scheme. Under the new system, every tracked hacking group receives a two-part name: a random but memorable first name, paired with a second word whose initial letter indicates the country of origin. Castle signifies China, Ion stands for Iran, Neptune denotes North Korea, and Relic marks Russia. It's a cleaner, more scalable approach — and given that Google now tracks more than 5,000 distinct "activity clusters" across numerous countries, scalability is no longer optional.

Cybersecurity analyst monitoring threat intelligence dashboards
Modern threat intelligence operations require tracking thousands of distinct hacking groups and activity clusters simultaneously.

Why Naming a Hacking Group Is a Strategic Security Decision

It might be tempting to dismiss the naming of hacking groups as a branding exercise or an internal bureaucratic quirk. It is neither. As Shane Huntley, CTO of Google's Threat Intelligence Group, has made clear, consistent naming is a foundational requirement for effective cyber defence. Without it, organisations cannot build institutional knowledge about the adversaries targeting them, share actionable intelligence across teams, or even ensure that different parts of the same organisation are talking about the same threat actor.

"If you actually get hacked by them or you're dealing with some incident, knowing how that actor behaves, what they do, what they've done in the past, all of these details become critically important to help the response and also work out your coverage against these threats as well."

— Shane Huntley, CTO, Google Threat Intelligence Group

The logic becomes even more compelling when you consider the operational realities. Security operations centre (SOC) teams responding to an incident in real time need to quickly determine whether the attacker is opportunistic ransomware or a disciplined state actor with persistent access objectives. That distinction changes everything: the containment strategy, the communication plan, the legal obligations under frameworks like GDPR, and the forensic depth required. If the attacker has been tracked and named, defenders have a starting point. If not, they are essentially working blind.

This is why resources like MITRE ATT&CK — which maps the tactics, techniques, and procedures (TTPs) of named threat actors — have become indispensable for security teams worldwide. According to MITRE's published documentation, the framework now references dozens of named groups, many of which carry multiple aliases across vendor naming schemes. The new Google system, by unifying the naming conventions of both its legacy Threat Analysis Group and the Mandiant team it acquired, reduces at least one layer of that fragmentation.

5,000 Threat Groups: The Scale Problem No One Talks About Enough

When cybersecurity companies began publishing threat intelligence reports in the early 2010s, the number of tracked groups was manageable. No one anticipated that, within roughly a decade, a single organisation would be monitoring more than 5,000 distinct clusters of malicious activity. Yet that is precisely where Google finds itself today, according to John Hultquist, chief analyst at Google Threat Intelligence Group.

5,000+Activity clusters tracked by Google Threat Intelligence
4Country codes in the new naming scheme (Castle, Ion, Neptune, Relic)
10+Years of fragmented vendor naming conventions now being rationalised
~190Nations with some form of documented cyber capability per independent research

What does this scale mean in practice? It means that Huntley's assertion — that very few developed nations lack their own cyber capabilities — is not hyperbole. It is a measured observation backed by years of intelligence collection. From sophisticated state actors like Russia's APT28 (now referred to within the Relic family under the new scheme) and China's prolific espionage operations (Castle-designated), to less publicised but increasingly capable actors in Southeast Asia, Eastern Europe, and the Middle East, the threat landscape is genuinely global.

For small business owners and entrepreneurs who might assume they are too small to be targeted, the data tells a different story. According to the Verizon Data Breach Investigations Report, small and medium-sized businesses are disproportionately represented in breach statistics precisely because they are seen as soft targets — often connected to larger supply chains that are the actual end goal. Understanding which groups target supply chains, and how they operate, is directly relevant to organisations of all sizes.

The proliferation of hacker-for-hire services and commercial spyware vendors — companies that sell offensive cyber capabilities to government clients around the world — adds another layer of complexity. These operators serve multiple customers across different geographies, making attribution exceptionally difficult. Huntley acknowledged this challenge directly, noting that spyware makers and hackers-for-hire are "slightly harder to track" due to their broad and varied client bases.

The Fragmentation Problem: Why Every Vendor Uses Different Names

One of the most persistent frustrations in the cybersecurity industry — particularly for IT decision-makers who must synthesise intelligence from multiple vendors, government advisories, and open-source feeds — is the lack of a universal naming convention. Fancy Bear (used by CrowdStrike) is the same group as APT28 (Mandiant's designation), Sofacy (used by Kaspersky), and STRONTIUM (Microsoft's name for the same actor). For a security analyst trying to correlate a threat report with an active incident, this fragmentation wastes time that organisations often do not have.

Threat Actor CrowdStrike Name Legacy Mandiant/Google Name Microsoft Name Origin
Russia GRU Unit 26165 Fancy Bear APT28 STRONTIUM Russia
North Korea Lazarus Labyrinth Chollima APT38 ZINC North Korea
China APT group Gothic Panda APT3 GOTHIC PANDA China
Iran cyber espionage Charming Kitten APT35 PHOSPHORUS Iran

The reason for this proliferation of names, as Huntley explained, is not stubbornness or competitive positioning — it is an honest reflection of epistemological limits. No single organisation has perfect visibility into every corner of the threat landscape. Each company's telemetry is shaped by its product footprint, its customer base, and its intelligence collection methods. When two vendors observe the same group from different angles, they may reach slightly different conclusions about how many subgroups exist, which campaigns are linked, and even which nation-state is responsible. Forcing a single name onto an imperfectly understood entity can create as many problems as it solves.

Huntley was candid about this: "No one has perfect visibility. We are building our model and our best understanding, but we will never know everything about what's going on." This epistemic humility is actually important context for privacy professionals and policymakers who rely on threat intelligence to make decisions. Attribution is probabilistic, not certain — and good policy should account for that uncertainty.

State-Sponsored vs. Criminal Hackers: Why the Distinction Matters for Digital Sovereignty

Not all hacking groups are created equal, and for organisations concerned with digital sovereignty and data protection, the distinction between state-sponsored actors and cybercriminal groups carries significant weight. State-sponsored hackers — the ones operating under nation-state mandates — tend to have more consistent targets, longer-term objectives, and more disciplined operational security. They are generally focused on espionage, intellectual property theft, election interference, or critical infrastructure disruption. Because their behaviour is relatively stable, they are easier to profile and predict once identified.

Digital threat landscape visualization representing state-sponsored cyber attacks
State-sponsored hacking groups operate with greater consistency and discipline than criminal organisations, making them more trackable — but no less dangerous.

Cybercriminal groups are structurally different. Their membership is fluid, their motivations are primarily financial, and they frequently splinter or rebrand after law enforcement actions or internal disputes. This makes consistent tracking far more difficult. A ransomware group that dissolves after an FBI takedown may reconstitute within months under a different name with overlapping membership. Understanding these dynamics is critical for organisations assessing their threat exposure under GDPR Article 32, which requires implementing "appropriate technical and organisational measures" against foreseeable threats.

For European organisations in particular, the geopolitical context cannot be separated from the cybersecurity context. The EU Agency for Cybersecurity (ENISA) publishes an annual Threat Landscape report that consistently identifies state-sponsored actors from Russia, China, North Korea, and Iran as primary threats to EU member state infrastructure and institutions. Google's naming revamp — which makes country of origin immediately legible from a group's name — aligns well with how policymakers and regulators think about cyber risk in geopolitical terms. A Castle-prefixed group is immediately identifiable as China-origin; a Relic-prefixed group signals Russia. For boards, legal teams, and incident response planners, that instant legibility has real operational value.

Originally reported by TechCrunch. Summarised and curated by European Purpose.