# Google Unified Threat Actor Naming: TAG and Mandiant Convergence

> Google unifies threat actor naming across TAG and Mandiant to streamline attribution and improve intelligence sharing for security operations teams.

- Published: 2026-07-28T10:39:08.000Z
- Severity: info
- Category: Threat Intel
- Tags: Google TAG, Mandiant, Threat Attribution, APT, Cybersecurity Standards
- Author: Runtime Rebel Intel
- Primary source: https://www.securityweek.com/google-adopts-new-threat-actor-naming-system/
- Canonical: https://runtimerebel.com/blog/google-unified-threat-actor-naming-tag-and-mandiant-convergence

## Key points

- Google is unifying its threat intelligence naming conventions to reduce confusion and improve communication across the global security community.
- Security teams, incident responders, and intelligence analysts relying on Google TAG or Mandiant reporting are the primary stakeholders affected.
- Organizations should update internal threat databases to map legacy Mandiant APT identifiers to the new two-word naming schema.

Google has announced a major consolidation of its cybersecurity intelligence efforts by unifying the naming conventions used by its Threat Analysis Group (TAG) and Mandiant. This transition, according to [SecurityWeek](https://www.securityweek.com/google-adopts-new-threat-actor-naming-system/), introduces a standardized two-word naming system designed to be more intuitive for defenders. This shift addresses the fragmentation often found in threat intelligence, where a single [APT](/glossary#apt) might be tracked under multiple aliases by different vendors, complicating the work of a [SOC](/glossary#soc).

## Structure of the Google Threat Actor Naming Convention

The new taxonomy utilizes a memorable adjective followed by a category-specific noun. The goal is to provide a naming schema that is easily recalled during an incident response while simultaneously conveying information about the actor's origins or primary motivations. Historically, Google TAG used identifiers like "FROZEN BARENTS" (a cluster associated with [Sandworm](https://en.wikipedia.org/wiki/Sandworm_(hacker_group))), while Mandiant utilized numeric designations like APT44. Under the unified system, these internal identifiers will align to provide a singular, authoritative reference point for telemetry and public reporting.

This move toward standardized "threat intelligence attribution standards" is part of a broader industry trend to simplify complex actor tracking. When a [SIEM](/glossary#siem) or [EDR](/glossary#edr) solution flags an [IoC](/glossary#ioc), the ability for an analyst to immediately associate the threat with a known entity—such as identifying a specific campaign as originating from [APT28](https://en.wikipedia.org/wiki/APT28) versus a financially motivated group—is vital for effective triage. 

## Benefits of Improving Threat Intelligence Attribution Standards

The lack of a universal [CVE](/glossary#cve) equivalent for threat actors has long been a hurdle for cross-platform collaboration. While the [MITRE ATT&CK](/glossary#mitre-att-ck) framework provides a shared language for [TTP](/glossary#ttp)s, naming has remained largely proprietary. By merging Mandiant's extensive historical database with TAG's deep visibility into consumer and enterprise ecosystems, Google provides a more comprehensive view of the threat landscape.

For security professionals, understanding **how to map Mandiant APT to Google naming** is a technical requirement for maintaining accurate threat models. The integration ensures that whether an organization is reviewing a report on a [Zero-Day](/glossary#zero-day) vulnerability or investigating a [Phishing](/glossary#phishing) campaign, the attribution terminology remains consistent. This consistency is particularly useful when tracking sophisticated operations involving [Lateral Movement](/glossary#lateral-movement) or complex [C2](/glossary#c2) infrastructure across global networks.

## Strategic Impact on Defensive Operations

Standardized naming helps organizations prioritize their defensive posture against specific threats, such as a [Supply Chain Attack](/glossary#supply-chain-attack) or a [Ransomware](/glossary#ransomware) deployment. By removing the ambiguity of multiple aliases, teams can more effectively search for historical data within their own logs. For example, when [Lazarus Group](https://en.wikipedia.org/wiki/Lazarus_Group) or [Volt Typhoon](https://en.wikipedia.org/wiki/Volt_Typhoon) is mentioned in a technical advisory, the use of a unified name allows for faster cross-referencing against internal security policies. 

Defenders should prioritize the update of internal playbooks to reflect these changes. As Google continues to integrate its security portfolio, this unified language will likely become a cornerstone of their threat intelligence platform, aiding in the identification of emerging threats before they result in a high-impact breach.

**Related:** [Multi-Threat Brief: AI Malware, Zimbra Exploits, Linux Kernel Flaws](/blog/multi-threat-brief-ai-malware-zimbra-exploits-linux-kernel-flaws), [North Korean APT Targets Developers via Malicious Tooling](/blog/north-korean-apt-targets-developers-via-malicious-tooling)

---

AI-generated analysis from the primary source above; not human-reviewed before publication — verify anything operational against the original (https://runtimerebel.com/editorial). Quote with attribution and a link to the canonical URL: https://runtimerebel.com/blog/google-unified-threat-actor-naming-tag-and-mandiant-convergence
