Updated Cyber Threat Actor Naming System
Google’s Threat Intelligence Group introduced a unified naming system for cyber threat actors, replacing fragmented historical labels with a standardized cryptonym format to improve clarity and operational efficiency for defenders.
Google Threat Intelligence Group (GTIG) announced a new naming taxonomy for cyber threat actors, merging separate systems previously maintained by Mandiant and Google’s Threat Analysis Group (TAG). The unified schema replaces inconsistent identifiers like APT1 with structured cryptonyms, aiming to reduce reliance on memorization and enhance intuitive threat tracking for security professionals. The system uses a two-word format: the first word reflects prior public reporting or a randomly generated term vetted by analysts, while the second categorizes actors by motivation, attribution, or activity type. This approach aligns with broader industry standards while prioritizing simplicity and usability in operational contexts.
The transition addresses longstanding challenges in cross-platform threat tracking, where disparate naming conventions hindered collaboration and analysis. GTIG emphasized that no single organization possesses complete visibility into the threat landscape, cautioning against direct comparisons between actors due to differing data sources. By simplifying the naming process, the new system seeks to streamline defense strategies and improve interoperability with other threat intelligence frameworks, such as MITRE ATT&CK mappings.
Initially, GTIG has prioritized renaming several dozen of the most active threat groups, with plans to expand the process on a rolling basis. Previous names will remain searchable within the Google Threat Intelligence (GTI) platform, and existing aliases from vendors like MITRE will be preserved to maintain continuity. The update includes a table listing new names for select prominent actors, appended to the announcement for reference.
For threat clusters still under early investigation, GTIG will continue using the UNC (uncategorized) designation, as outlined in prior documentation. The shift to cryptonyms represents a practical effort to manage the complexity of tracking evolving cyber threats, though GTIG acknowledges that the system’s effectiveness depends on ongoing refinement and community adoption.