Google's top hacker hunter explains why hacking groups get codenames
Shane Huntley from Google Threat Intelligence explains the overhaul of the company's hacker naming system as it tracks over 5,000 threat groups worldwide.

Stock photo for illustration only, not from the actual event
- Google overhauls its hacker naming system, phasing out identifiers like APT1 and APT41.
- The new system uses a memorable, random first name and a second word indicating the country of origin.
- Google currently tracks more than 5,000 activity clusters across multiple nations.
- Consistent naming helps organizations understand attacker behavior and respond to incidents faster.
For over a decade, the cybersecurity industry has assigned names to different hacking groups. While names like Fancy Bear became mainstream due to high-profile attacks, industry insiders often struggle to keep track of them because every company uses a different naming convention. To address this, Google rolled out a major revamp of its hacker naming system in August 2026.
Gone are the days of designations like APT1, APT41, or any other numbers from the legacy system adopted by Mandiant, the security firm now integrated into Google. Under the updated framework, Google's naming scheme is straightforward: a hacking group receives a memorable, random first name followed by a second word whose initial letter designates the country of origin—Castle for China, Ion for Iran, Neptune for North Korea, and Relic for Russia.
Shane Huntley, chief technology officer of the Google Threat Intelligence Group, told TechCrunch that the overhaul was necessary to bring clarity to security researchers both internally and externally. In the early 2010s, when companies first began publishing cyberattack reports, Huntley noted that they never anticipated dealing with as many threat groups as exist today.

Stock photo for illustration only, not from the actual event
According to John Hultquist, chief analyst at the Google Threat Intelligence Group, the company currently tracks more than 5,000 activity clusters across several nations. Huntley added that very few developed countries lack their own cyber capabilities and associated hacking groups.
"we were not expecting to have as many threat groups as we do today."
Shane Huntley, Google Threat Intelligence Group
Assigning names to hacking groups serves a practical purpose beyond academic exercise. The primary goal is establishing a baseline understanding of who is attacking whom and their methods, allowing organizations to recognize threats swiftly, prepare defenses, and investigate incidents promptly. Huntley emphasized that achieving this requires consistent naming and tracking of threat actors.
Google's unified naming approach highlights the evolving complexity of modern cyber warfare. By embedding country-of-origin indicators into the codenames, security analysts can immediately contextualize geopolitical threats during an incident response. Although industry-wide consensus remains elusive due to varying proprietary telemetry datasets, consolidating Google's Threat Analysis Group and Mandiant taxonomies eliminates a layer of fragmentation.
While state-sponsored actors like North Korea's Lazarus Group exhibit relatively consistent behaviors and targets, tracking cybercriminal syndicates and hacker-for-hire outfits remains considerably more challenging. Cybercriminals frequently shift alliances and fracture, whereas commercial spyware vendors and mercenary hackers maintain diverse global client bases that complicate attribution efforts.
Source: TechCrunch
Found something wrong in this article? Report an issue with this article
Comments
Leave a Comment