Google has unveiled a new cryptonym-based naming convention for identifying threat actors through its Threat Intelligence Group (GTIG), aiming to streamline the process and enhance clarity in cybersecurity tracking.
Innovative Naming Approach
The new system abandons the use of sequential numbers and various disparate identifiers. Instead, Google is opting for unique two-word combinations to label each activity cluster. This approach is designed to make it easier for organizations to map and understand threat actors.
Each activity cluster’s first word will be a memorable term that may have been previously used in public reports to represent the threat actor. If no such term exists, a randomly generated word will be used. The second word categorizes the threat actor by motivation, attribution, or activity type, providing further context.
Categorization of Threat Actors
Google has categorized threat actors based on their geographic or operational origins. For instance, ‘Castle’ will denote Chinese threat actors, ‘Ion’ for those from Iran, ‘Neptune’ for North Korean groups, ‘Relic’ for Russian actors, and ‘Comet’ for cybercriminal gangs. This structured approach facilitates easier identification and tracking.
An example of this naming system in action is Russia’s notorious Sandworm group, previously tracked as ‘APT44’, now named ‘Sandworm Relic’. This change simplifies the tracking process, as the group has been previously known by various names such as Blue Echidna and Voodoo Bear.
Streamlining Cybersecurity Operations
Google acknowledges the complexity of existing threat actor tracking systems and aims to simplify these with its new naming convention. This move is intended to aid in mapping other naming taxonomies and streamline operations across the industry.
The change addresses the challenge of varying visibility levels among cybersecurity organizations, which makes direct comparisons between threat actors difficult. By offering a more intuitive naming system, Google aims to mitigate these challenges.
To initiate this transition, Google has already renamed several of the most active threat actors, a process that will continue progressively. Previous threat actor names will remain accessible and indexed within the Google Threat Intelligence (GTI) platform, complete with MITRE ATT&CK mappings and other vendor aliases.
Google will retain the UNC designation for threat clusters that are yet to be categorized under this new system.
Future Outlook
This transition to a simpler naming system marks a significant step towards enhancing cybersecurity operations. By providing a more consistent framework, Google aims to improve the clarity and efficiency of threat actor tracking, which is crucial in the evolving landscape of cyber threats.
