Google Explains Why Cybersecurity Teams Assign Codenames to Hacking Groups
Tech

Google Explains Why Cybersecurity Teams Assign Codenames to Hacking Groups

TechNews Editorial
TechNews EditorialAug 8, 2026 · 4 min read
Share

For more than a decade, the cybersecurity industry has assigned names to various hacking groups. Some names like Fancy Bear crossed into the mainstream through prominent attacks. Others remain known only inside the cybersecurity industry. Industry insiders often struggle to keep track because every company uses a different naming system. Last month, Google revamped its own naming system for hacking groups.

Google replaced older designations like APT1 and APT41 originating from Mandiant, an independent security firm now owned by Google. Mandiant pioneered the early naming scheme. Under Google's new system, a hacking group receives a random first name and a second word with an initial indicating the country of origin. Castle designates China, Ion designates Iran, Neptune designates North Korea, and Relic designates Russia.

Shane Huntley, chief technology officer of the Google Threat Intelligence Group, stated that the revamp brings clarity to security researchers internally and externally. In the early 2010s, security companies began publishing reports on cyberattacks and naming the hackers. Huntley told TechCrunch that they did not expect to have as many threat groups as exist today. Google now tracks more than 5,000 activity clusters across several countries, according to John Hultquist, chief analyst at the Google Threat Intelligence Group. Huntley noted that very few developed nations lack their own cyber capabilities and hacking groups.

Naming hacking groups serves a practical purpose beyond an academic exercise. The goal is establishing a baseline understanding of who attacks whom and the methods they use. Organizations can recognize threats quickly, prepare defenses, stop attacks, or investigate incidents promptly. Huntley explained that this requires consistent naming and tracking.

Huntley emphasized that knowing how specific actors behave and what they did in the past helps incident response and threat coverage. Understanding the goals and affiliations of North Korean government hackers known as the Lazarus Group gives defenders a starting point. State-sponsored hackers are easier to track than cybercriminal groups and hackers-for-hire because state actors maintain more consistent targets and activities. Cybercriminal groups feature members who come and go, while hacker-for-hire groups and spyware makers serve multiple customers worldwide.

Critics frequently ask why all companies do not use identical codenames. Huntley explained that every company maintains a distinct view of each group based on unique data and telemetry. Sharing more information does not eliminate this variation. Huntley stated that no one possesses perfect visibility, noting that companies build models based on their best understanding without ever knowing everything.

Google unified the naming schemes of its Threat Analysis Group and Mandiant to reduce the number of systems to remember. Cybersecurity professionals and the public continue to rely on reference resources to navigate the different naming conventions used across the industry.

Related Stories