Business / news

Google overhauls hacking group naming system, sheds APT numbers

Google has introduced a new way of naming hacking groups, replacing obscure APT numbers with memorable first names and a second word that signals the group’s country of origin.

The change, rolled out last month, abandons the long-used APT1, APT41 and similar identifiers that were popularized by Mandiant, the security firm now part of Google.

Under the new scheme, each hacking group receives a random, memorable first name followed by a second word whose starting letter indicates the country of origin. For example, Castle refers to China, Ion to Iran, Neptune to North Korea and Relic to Russia.

The cybersecurity industry has spent more than a decade assigning codenames to hacking groups, from the well-known Fancy Bear to dozens of lesser-known clusters. But naming has often been inconsistent across companies, making it difficult for insiders, policymakers and the public to keep track.

Google’s leading threat intelligence expert said the shift is meant to make threat actors easier to identify and remember, while reducing confusion caused by overlapping and inconsistent labels. Dedicated resources already exist to map these names, but the new system aims to bring greater clarity to the field.