Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Google Introduces New Naming System for Threat Actors

Google Introduces New Naming System for Threat Actors

Posted on July 28, 2026 By CWS

Google has unveiled a new cryptonym-based naming convention for identifying threat actors through its Threat Intelligence Group (GTIG), aiming to streamline the process and enhance clarity in cybersecurity tracking.

Innovative Naming Approach

The new system abandons the use of sequential numbers and various disparate identifiers. Instead, Google is opting for unique two-word combinations to label each activity cluster. This approach is designed to make it easier for organizations to map and understand threat actors.

Each activity cluster’s first word will be a memorable term that may have been previously used in public reports to represent the threat actor. If no such term exists, a randomly generated word will be used. The second word categorizes the threat actor by motivation, attribution, or activity type, providing further context.

Categorization of Threat Actors

Google has categorized threat actors based on their geographic or operational origins. For instance, ‘Castle’ will denote Chinese threat actors, ‘Ion’ for those from Iran, ‘Neptune’ for North Korean groups, ‘Relic’ for Russian actors, and ‘Comet’ for cybercriminal gangs. This structured approach facilitates easier identification and tracking.

An example of this naming system in action is Russia’s notorious Sandworm group, previously tracked as ‘APT44’, now named ‘Sandworm Relic’. This change simplifies the tracking process, as the group has been previously known by various names such as Blue Echidna and Voodoo Bear.

Streamlining Cybersecurity Operations

Google acknowledges the complexity of existing threat actor tracking systems and aims to simplify these with its new naming convention. This move is intended to aid in mapping other naming taxonomies and streamline operations across the industry.

The change addresses the challenge of varying visibility levels among cybersecurity organizations, which makes direct comparisons between threat actors difficult. By offering a more intuitive naming system, Google aims to mitigate these challenges.

To initiate this transition, Google has already renamed several of the most active threat actors, a process that will continue progressively. Previous threat actor names will remain accessible and indexed within the Google Threat Intelligence (GTI) platform, complete with MITRE ATT&CK mappings and other vendor aliases.

Google will retain the UNC designation for threat clusters that are yet to be categorized under this new system.

Future Outlook

This transition to a simpler naming system marks a significant step towards enhancing cybersecurity operations. By providing a more consistent framework, Google aims to improve the clarity and efficiency of threat actor tracking, which is crucial in the evolving landscape of cyber threats.

Security Week News Tags:APT, cryptonym, cyber defense, cyber threats, Cybercrime, Cybersecurity, Google, GTIG, naming system, Threat Actors

Post navigation

Previous Post: Critical Vulnerabilities in LoadMaster Demand Immediate Updates
Next Post: Critical FFmpeg Vulnerabilities Demand Urgent Updates

Related Posts

Webinar Today: The Future of Industrial Network Security Webinar Today: The Future of Industrial Network Security Security Week News
Iranian Cyber Attackers Deploy Versatile C&C System Iranian Cyber Attackers Deploy Versatile C&C System Security Week News
Trend Micro and Others Patch Critical Security Flaws Trend Micro and Others Patch Critical Security Flaws Security Week News
US Deportation Airline GlobalX Confirms Hack US Deportation Airline GlobalX Confirms Hack Security Week News
Cyberattack Targets International Criminal Court Cyberattack Targets International Criminal Court Security Week News
Sophisticated Koske Linux Malware Developed With AI Aid Sophisticated Koske Linux Malware Developed With AI Aid Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Microsoft Teams Vishing Attack Exploits Quick Assist
  • Critical TeamCity Vulnerability Demands Immediate Update
  • Critical FFmpeg Vulnerabilities Demand Urgent Updates
  • Google Introduces New Naming System for Threat Actors
  • Critical Vulnerabilities in LoadMaster Demand Immediate Updates

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Microsoft Teams Vishing Attack Exploits Quick Assist
  • Critical TeamCity Vulnerability Demands Immediate Update
  • Critical FFmpeg Vulnerabilities Demand Urgent Updates
  • Google Introduces New Naming System for Threat Actors
  • Critical Vulnerabilities in LoadMaster Demand Immediate Updates

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark