Google Introduces New Hacker Group Naming System Amid Rising Cyber Threats
Google has updated its system for identifying hacking groups to bring clarity to researchers and organizations tracking cyber threats. The old naming system, introduced by Mandiant, used designations like APT1 and APT41. However, with over 5,000 active threat clusters across several countries, Google's Threat Intelligence Group found it necessary to rethink the system.
The new system is relatively simple: the first part of the name is memorable and random, while the second indicates the country of origin - Castle for China, Ion for Iran, Neptune for North Korea, and Relic for Russia. This change is expected to make understanding threats faster and more consistent, providing a foundation for quicker responses and more effective action against cyberattacks in the future.
The main benefit of this system lies not only in theoretical analysis but also in developing a basic understanding of who is attacking, whom they are targeting, and how they operate. By knowing the behavior of threat actors and their past actions, organizations can recognize threats more quickly, prepare for them, neutralize incidents, or investigate them more efficiently.
Shane Huntley, Google Threat Intelligence Group's chief technology officer, emphasized that there is virtually no developed country without its own cyber capabilities and threat groups. He also noted that relying on behavioral data helps organizations respond to crises and provides a starting point for defending against this type of threat.