Why hacking groups get codenames, per Google’s top hunter

▼ Summary
– Google replaced Mandiant-style numeric names (APT1, APT41) with a system using a memorable first name and a country-coded second word, such as Castle for China, Ion for Iran, Neptune for North Korea, and Relic for Russia.
– The revamp addresses confusion from inconsistent naming across companies, as Google now tracks over 5,000 hacking activity clusters in many countries.
– Naming groups aids defense by establishing baseline knowledge of hacker behavior, goals, and methods, enabling faster threat recognition and incident response.
– Tracking state-sponsored hackers is easier than tracking cybercriminal groups or hackers-for-hire, which have more fluid memberships and diverse customers.
– Uniform codenames across all companies are impossible because each firm has different data and visibility, so no single model fully captures any group’s activities.
For over a decade, the cybersecurity world has operated with a sprawling, sometimes chaotic system of codenames for hacker groups. Some monikers, such as Fancy Bear, have achieved near-mainstream fame due to high-profile attacks and catchy titles. The vast majority, however, remain obscure, known only to a niche circle of threat researchers and industry insiders.
Even those inside the field frequently struggle to keep up. A significant reason for the confusion is that no two security vendors label the same adversary identically. To address this fragmentation, resources have emerged that aim to serve as a central reference point for professionals, government agencies, journalists, and the public to decipher the digital threat landscape.
In a move to streamline its own internal tracking, Google recently overhauled its nomenclature for state-sponsored hacking entities.
The era of sterile designations like APT1 or APT41, a numerical system popularized by Mandiant (now a Google subsidiary and the first to adopt such a framework), is over. Google’s new methodology is straightforward: each group receives a memorable, random first name paired with a second word whose initial denotes the suspected country of origin. For instance, “Castle” points to China, “Ion” to Iran, “Neptune” to North Korea, and “Relic” to Russia.
Shane Huntley, Chief Technology Officer of Google Threat Intelligence Group, explained that this shift was driven by a need for clarity, both for internal researchers and the broader security ecosystem. Speaking with TechCrunch, Huntley noted that when these naming conventions first emerged in the early 2010s, the industry underestimated the sheer volume of threat actors that would eventually surface. Today, Google monitors more than 5,000 distinct “activity clusters” globally, according to John Hultquist, Chief Analyst at the group. Huntley added that virtually every developed nation now possesses its own offensive cyber capabilities.
But why bother assigning names at all? Huntley emphasizes that this is far more than a bureaucratic exercise. Establishing a consistent identity for a hacking group allows defenders to build a baseline profile of their behavior, tactics, and targets. This foundational knowledge enables organizations to recognize threats faster, bolster their defenses, and accelerate incident response.
“If you actually get hacked by them or you’re dealing with some incident, knowing how that actor behaves, what they do, what they’ve done in the past, all of these details become critically important to help the response and also work out your coverage against these threats as well,” Huntley stated. For example, familiarity with the North Korean state-sponsored Lazarus Group’s operational patterns gives defenders a crucial head start when investigating a breach.
While tracking government-backed hackers is complex, Huntley points out that it is often more straightforward than following cybercriminal syndicates or hackers-for-hire. State-sponsored actors tend to have consistent targets and strategic objectives. In contrast, criminal groups are fluid, with members who frequently splinter or change allegiances. Similarly, mercenary hacking outfits and spyware vendors serve a diverse clientele worldwide, making their operational footprints harder to pin down.
A frequent critique leveled at the industry is the lack of a unified naming standard. Why can’t security firms simply agree on one codename per group? Huntley argues that this ideal is unattainable. Each company operates with its own unique telemetry and data sets, resulting in different perspectives on the same adversary. He contends that even enhanced information sharing cannot bridge these fundamental gaps in visibility.
“No one has perfect visibility,” he said. “We are building our model and our best understanding, but we will never know everything about what’s going on.”
By merging the naming conventions of Google’s former Threat Analysis Group and Mandiant, the company has eliminated at least one layer of complexity. For the remaining cacophony of codenames across the industry, researchers and interested onlookers will have to consult the ever-expanding public databases that attempt to catalog them all.
(Source: TechCrunch)




