Google has introduced a refreshed system for labeling hacking groups, aiming to make cyber threat tracking clearer for researchers and security teams. The update replaces older number-based labels such as APT-style codes with a more readable format.
Under the new approach, each group receives a memorable first name followed by a second word that signals a likely country association: Castle for China, Ion for Iran, Neptune for North Korea, and Relic for Russia. The company says the change is designed to reduce confusion across the cybersecurity field.
Shane Huntley, chief technology officer of Google Threat Intelligence Group, said the updated naming model helps analysts build a shared baseline for understanding how threat actors operate. That, in turn, can support faster detection, better preparation, and more informed incident response.
Google now monitors more than 5,000 activity clusters across multiple countries, according to John Hultquist, chief analyst at Google Threat Intelligence Group. Huntley noted that while state-backed groups are often easier to follow because of their more consistent behavior, cybercriminal networks and hacker-for-hire operations can be harder to map due to shifting members and broader customer bases.
The company's move also brings together naming practices from Google Threat Intelligence and Mandiant, creating a more unified framework for internal and external use. Even so, Huntley emphasized that no organization has complete visibility into the cyber landscape.
As digital threats grow more complex, clearer naming systems could help shape a more coordinated and responsive cybersecurity future.