Google's New Naming Scheme Aims to Tame the Chaos of Cybersecurity Threats
Google's top hacker hunter explains why naming hacking groups is crucial for cybersecurity. Shane Huntley, chief technology officer of Google Threat Intelligence Group, says that over a decade ago, companies started publishing reports on cyberattacks and naming hackers behind them.
The problem was that every company had its own way of naming hacking groups, making it hard to keep track. This led to the creation of resources like this one, which tries to be a one-stop shop for cybersecurity professionals, government officials, policymakers, journalists, and the wider public to understand who is who.
Last month, Google revamped its naming system for hacking groups. Gone are the days of APT1, APT41, or APT whatever number, which was the system adopted by Mandiant, now part of Google.
According to Huntley, the new system is relatively simple: a hacking group will have a first name that is memorable and random, and a second word whose initial indicates the country of origin. For example, Castle for China, Ion for Iran, Neptune for North Korea, and Relic for Russia.