Skip to main content
root@rebel:~$ cd /news/threats/google-threat-intel-adopts-unified-cryptonym-naming-for-actors_
[TIMESTAMP: 2026-07-24 13:55 UTC] [AUTHOR: Runtime Rebel Intel] [SEVERITY: INFO]

Google Threat Intel Adopts Unified Cryptonym Naming for Actors

INFO Threat Intel #Mandiant
AI-generated analysis
READ_TIME: 4 min read
Primary source: cloud.google.com

This article was written by a language model from the source above and was not reviewed by a human before publication. Verify anything operational against the original. Editorial policy

// executive briefing tl;dr
  • [01] Defenders gain clearer, more intuitive threat actor identification through a new unified naming system.
  • [02] Applies to all intelligence consumed from Google Threat Intelligence's platform and public reporting.
  • [03] Familiarize with GTIG's new cryptonym-based threat actor taxonomy for improved threat context.

Google Threat Intelligence Standardizes Actor Naming

Google Threat Intelligence Group (GTIG) has announced the implementation of a unified naming schema for tracking cyber threat actors. This strategic shift aims to standardize threat actor identification across various platforms and public reporting, streamlining intelligence consumption for security professionals. This new taxonomy replaces the previously distinct systems maintained by Mandiant and Google’s Threat Analysis Group (TAG), which had evolved independently over time, according to Google’s official announcement.

The move towards a fused tracking system within GTIG necessitated a new, more intuitive naming convention. The goal is to move beyond disparate identifiers like “APT1” or sequential numbers, which often lack the critical context necessary for rapid defensive operations. The updated system is designed to align with industry-standard threat actor naming systems while emphasizing ease of understanding and recall.

The New Google Threat Actor Naming Convention

GTIG’s new schema employs a cryptonym-based approach, utilizing memorable two-word combinations for each distinct threat actor. This design is rooted in providing immediate contextual information to defenders, reducing the need for extensive memorization and accelerating incident response.

Each cryptonym follows a specific structure:

  • The first word: A unique and memorable term chosen to represent the specific actor. This word may reflect names previously used in public reporting. If no such term exists, it is randomly generated to prevent bias and then vetted by GTIG analysts.
  • The second word: Categorizes threat clusters based on primary motivation, attribution, or activity type. This category is selected based on what GTIG considers most critical for defense and response strategies.

For instance, the source provides examples of how certain origins or types map to the second word in the cryptonym:

  • People’s Republic of China: CASTLE
  • Iran: ION
  • North Korea: NEPTUNE
  • Russia: RELIC
  • Cybercriminal: COMET

This GTIG cryptonym schema explanation provides a clear and immediate understanding of a group’s likely origin or primary operational characteristic, which is invaluable for security teams assessing potential threats.

Implications for Threat Intelligence Consumption

This standardization benefits security professionals by fostering a more consistent and intuitive understanding of the threat landscape. Organizations that consume Google’s threat intelligence will find it easier to correlate information and understand the nature of the actors involved without needing to cross-reference multiple, potentially conflicting, naming schemes. The new system emphasizes context over arbitrary identifiers, allowing for quicker decision-making and better allocation of resources.

GTIG acknowledges that direct, apples-to-apples comparisons between threat actors across different organizations are rarely possible due to varying visibility into the threat landscape. However, by adopting a simpler, more intuitive convention, GTIG aims to make its intelligence more accessible and actionable. This mapping Google threat intelligence actors will be crucial for defenders to understand the nuances of various campaigns and TTPs associated with these groups.

The transition is a work in progress, with GTIG initially prioritizing the renaming of several dozen of the most active groups. Importantly, previous names will remain indexed and searchable within the Google Threat Intelligence (GTI) platform, with MITRE ATT&CK mappings and other vendor aliases preserved. For threat clusters still under early investigation, GTIG will continue to use UNC, or “uncategorized,” designations.

Actionable Recommendations for Defenders

Security professionals should take the following steps to adapt to and leverage GTIG’s new threat actor naming system:

  • Familiarize with the new schema: Review GTIG’s updated documentation and understand the logic behind the two-word cryptonyms, particularly the contextual meaning of the second word.
  • Update internal processes: Adjust internal threat intelligence parsing and reporting mechanisms to align with the new GTIG naming convention where applicable. This ensures consistency in internal discussions and external intelligence sharing.
  • Leverage contextual information: Utilize the inherent context provided by the cryptonyms (e.g., origin, motivation) to prioritize threat responses and tailor defensive strategies more effectively. This can significantly improve the efficiency of a SOC team.
  • Consult GTI platform: When encountering unfamiliar names, use the GTI platform to cross-reference and access historical data, MITRE ATT&CK mappings, and other aliases that remain indexed.

Advertisement

Advertisement