Skip to main content

Google's top hacker hunter explains why hacking groups get codenames

Shane Huntley from Google Threat Intelligence explains the overhaul of the company's hacker naming system as it tracks over 5,000 threat groups worldwide.

AI-written
Inewgen
08 Aug 2026Source: TechCrunch3 min read (0 views)
Share
Google's top hacker hunter explains why hacking groups get codenames

Stock photo for illustration only, not from the actual event

Font size
  • Google overhauls its hacker naming system, phasing out identifiers like APT1 and APT41.
  • The new system uses a memorable, random first name and a second word indicating the country of origin.
  • Google currently tracks more than 5,000 activity clusters across multiple nations.
  • Consistent naming helps organizations understand attacker behavior and respond to incidents faster.

For over a decade, the cybersecurity industry has assigned names to different hacking groups. While names like Fancy Bear became mainstream due to high-profile attacks, industry insiders often struggle to keep track of them because every company uses a different naming convention. To address this, Google rolled out a major revamp of its hacker naming system in August 2026.

Gone are the days of designations like APT1, APT41, or any other numbers from the legacy system adopted by Mandiant, the security firm now integrated into Google. Under the updated framework, Google's naming scheme is straightforward: a hacking group receives a memorable, random first name followed by a second word whose initial letter designates the country of origin—Castle for China, Ion for Iran, Neptune for North Korea, and Relic for Russia.

Shane Huntley, chief technology officer of the Google Threat Intelligence Group, told TechCrunch that the overhaul was necessary to bring clarity to security researchers both internally and externally. In the early 2010s, when companies first began publishing cyberattack reports, Huntley noted that they never anticipated dealing with as many threat groups as exist today.

cyber threat intelligence data analysis screen

Stock photo for illustration only, not from the actual event

5,000+Threat groups tracked by Google

According to John Hultquist, chief analyst at the Google Threat Intelligence Group, the company currently tracks more than 5,000 activity clusters across several nations. Huntley added that very few developed countries lack their own cyber capabilities and associated hacking groups.

Never miss the latest news?

Subscribe to get news summaries by email - not often enough to be annoying.

โฆษณา

"we were not expecting to have as many threat groups as we do today."

Shane Huntley, Google Threat Intelligence Group

Assigning names to hacking groups serves a practical purpose beyond academic exercise. The primary goal is establishing a baseline understanding of who is attacking whom and their methods, allowing organizations to recognize threats swiftly, prepare defenses, and investigate incidents promptly. Huntley emphasized that achieving this requires consistent naming and tracking of threat actors.

Google's unified naming approach highlights the evolving complexity of modern cyber warfare. By embedding country-of-origin indicators into the codenames, security analysts can immediately contextualize geopolitical threats during an incident response. Although industry-wide consensus remains elusive due to varying proprietary telemetry datasets, consolidating Google's Threat Analysis Group and Mandiant taxonomies eliminates a layer of fragmentation.

While state-sponsored actors like North Korea's Lazarus Group exhibit relatively consistent behaviors and targets, tracking cybercriminal syndicates and hacker-for-hire outfits remains considerably more challenging. Cybercriminals frequently shift alliances and fracture, whereas commercial spyware vendors and mercenary hackers maintain diverse global client bases that complicate attribution efforts.

Source: TechCrunch

Comments

Leave a Comment
0/2000

Found something wrong in this article? Report an issue with this article