Google Standardizes Nation-State Hacker Naming Convention
Google's Mandiant division has overhauled its naming convention for Advanced Persistent Threat (APT) groups, aiming to standardize how the cybersecurity industry tracks nation-state hackers. This move comes as the threat landscape continues to evolve and fragment.
The old system, which was pioneered by Mandiant, assigned codenames such as APT1, APT28, and APT29. However, this standardization broke down as the number of threat groups tripled since 2020, with over 300 distinct groups now tracked by Google's Cloud Security Report.
The new system aims to cut through confusion caused by multiple naming schemes used by different vendors, such as Microsoft's weather-themed taxonomy and CrowdStrike's animal-based approach. By leveraging its unique position of historical credibility and AI capabilities, Mandiant seeks to push the industry toward better coordination and interoperability.