ByteBulletin

[tooling] · · 2 min read

Google overhauls hacker codenames: say goodbye to APT1, hello to 'Castle' and 'Ion'

Google's revamped naming system for hacking groups aims to bring clarity to a crowded field of threat actors.

By ByteBulletin Editors · Editorial Team


For years, cybersecurity researchers have struggled to keep track of the growing number of hacking groups, each with its own set of code names. Last month, Google decided to do something about it, revamping its naming system for threat actors in a move that could set a new standard for the industry.

The old system, inherited from Mandiant, the security firm Google acquired in 2022, relied on alphanumeric designations like APT1 or APT41. While functional, these names were notoriously hard to remember and even harder to keep straight, especially as the number of tracked groups exploded. Google now tracks more than 5,000 "activity clusters" across the globe, according to John Hultquist, chief analyst at Google Threat Intelligence Group.

Under the new system, each hacking group gets a memorable, random first name and a second word whose initial indicates the country of origin: "Castle" for China, "Ion" for Iran, "Neptune" for North Korea, and "Relic" for Russia. For example, a Chinese group might be called "Sandy Castle," while a Russian group could be "Frosty Relic." The change was announced in a blog post by Shane Huntley, CTO of Google Threat Intelligence Group, who said the goal is to make it easier for researchers and defenders to track and communicate about threat actors.

Both Huntley and Hultquist emphasized that the naming system is more than just a matter of convenience. It's a critical part of how organizations defend themselves. When a company is hacked, knowing that the attacker is, say, the Lazarus Group—a North Korean state-sponsored group with a well-documented history—gives defenders a significant head start. They can anticipate the group's tools, tactics, and preferred targets, and prepare accordingly.

"If you actually get hacked by them or you're dealing with some incident, knowing how that actor behaves, what they do, what they've done in the past, all of these details become critically important to help the response and also work out your coverage against these threats as well," Huntley said.

One might wonder why the industry doesn't just adopt a single, unified naming scheme. Huntley explained that it's not that simple. Every security firm has its own visibility into the threat landscape, based on its unique telemetry and data sources. As a result, each company tends to group and name actors slightly differently. "No one has perfect visibility," he said.

Despite the challenges, Google's move is a step toward simplifying a notoriously complex field. For developers and security professionals, this means one less headache when trying to correlate threat reports from different sources. The new names may not be as catchy as "Fancy Bear," but they're certainly more descriptive. And that's a win for everyone trying to make sense of the ever-evolving cyber threat landscape.

SHARE

← All stories