OFICIAL Google Cloud Threat Intelligence

Updated Cyber Threat Actor Naming System

What happened
Based on Google Cloud Threat Intelligence · Jul 24, 2026

Google’s Threat Intelligence Group introduced a unified naming system for cyber threat actors, replacing fragmented historical labels with a standardized cryptonym format to improve clarity and operational efficiency for defenders.

Updated Cyber Threat Actor Naming System
Google Cloud Threat Intelligence — Google
Key points
·
Visibility and context on the threats that matter most.
·
Update (July 30): A table listing the new names of select prominent threat actors was appended to this post.
·
Today, Google Threat Intelligence Group (GTIG) will begin rolling out a unified naming schema for tracking threat actors.
·
This new naming taxonomy represents an effort to standardize tracking across platforms and public reporting.

Google Threat Intelligence Group (GTIG) announced a new naming taxonomy for cyber threat actors, merging separate systems previously maintained by Mandiant and Google’s Threat Analysis Group (TAG). The unified schema replaces inconsistent identifiers like APT1 with structured cryptonyms, aiming to reduce reliance on memorization and enhance intuitive threat tracking for security professionals. The system uses a two-word format: the first word reflects prior public reporting or a randomly generated term vetted by analysts, while the second categorizes actors by motivation, attribution, or activity type. This approach aligns with broader industry standards while prioritizing simplicity and usability in operational contexts.

The transition addresses longstanding challenges in cross-platform threat tracking, where disparate naming conventions hindered collaboration and analysis. GTIG emphasized that no single organization possesses complete visibility into the threat landscape, cautioning against direct comparisons between actors due to differing data sources. By simplifying the naming process, the new system seeks to streamline defense strategies and improve interoperability with other threat intelligence frameworks, such as MITRE ATT&CK mappings.

Initially, GTIG has prioritized renaming several dozen of the most active threat groups, with plans to expand the process on a rolling basis. Previous names will remain searchable within the Google Threat Intelligence (GTI) platform, and existing aliases from vendors like MITRE will be preserved to maintain continuity. The update includes a table listing new names for select prominent actors, appended to the announcement for reference.

For threat clusters still under early investigation, GTIG will continue using the UNC (uncategorized) designation, as outlined in prior documentation. The shift to cryptonyms represents a practical effort to manage the complexity of tracking evolving cyber threats, though GTIG acknowledges that the system’s effectiveness depends on ongoing refinement and community adoption.

Original source → Deals on Clipraptor.com →