
Google has unveiled a new standardized naming system for cyber threat groups, aiming to simplify the way cybersecurity professionals identify, track, and discuss malicious actors. The initiative, introduced by Google Threat Intelligence (GTIG), seeks to eliminate the confusion caused by the multiple naming conventions used by different cybersecurity vendors and researchers. By assigning a unique and consistent identifier to every major threat group, Google hopes to create a common language that can be used across the global cybersecurity community.
The concept is comparable to the scientific classification system used by biologists to identify plants and animals. Just as every species has a universally recognized scientific name, Google’s framework provides cyber threat groups with standardized names that can be referenced by security researchers, governments, businesses, and law enforcement agencies. This approach is expected to make threat intelligence easier to understand and improve collaboration among organizations working to combat cybercrime.
Under the new nomenclature, threat groups believed to be associated with different countries are assigned distinct names. For instance, cyber threat actors linked to China will be categorized under the name Castle, while those associated with Iran will be identified as ION. Similarly, North Korean threat groups will be referred to as Neptune, and Russian cyber actors will carry the identifier, Relic. These names are intended to serve as neutral reference points rather than political labels, helping analysts distinguish between different threat clusters without relying on inconsistent terminology.
According to Google Threat Intelligence, the primary objective of the initiative is to establish a unified naming framework that improves clarity and consistency in cyber threat reporting. In the past, the same hacking group has often been assigned different names by separate cybersecurity companies, creating unnecessary confusion for security teams trying to correlate reports and intelligence. A single standardized naming system allows analysts to identify the same threat actor more quickly and reduces the risk of misunderstandings during investigations.
The framework also considers important characteristics such as a threat group’s motivation, attribution, operational methods, and overall objectives. By organizing threat actors under a structured naming convention, Google aims to make it easier for incident response teams and security operations centers to analyze attacks, share intelligence, and coordinate defensive measures.
As cyberattacks continue to grow in sophistication and frequency, effective communication has become increasingly important. A consistent naming system enables organizations to respond more efficiently to emerging threats, improves information sharing between public and private sectors, and enhances the accuracy of threat intelligence reporting. While the new nomenclature will not replace the technical analysis required to investigate cyber incidents, it provides a valuable foundation for standardizing discussions about cyber threat actors.
Google’s initiative is expected to contribute to stronger collaboration within the cybersecurity industry and help security professionals respond more effectively to the evolving global threat landscape.
Join our LinkedIn group Information Security Community!










