
Updated Cyber Threat Actor Naming System
Google Threat Intelligence Group is implementing a unified, cryptonym-based naming schema to standardize how they track and report on cyber threat actors.
Why it matters
This change allows security defenders to identify threats more intuitively by replacing complex identifiers with memorable names that indicate an actor's origin or motivation.
The details
- The system uses two-word cryptonyms combining a unique term with a category word.
- Category words include CASTLE for China, ION for Iran, and RELIC for Russia.
- Previous actor names and MITRE ATT&CK mappings remain searchable in the GTI platform.
Show entities and relationshipsHide entities and relationships
In this article
Countries
Products
Key connections
Google owns Google Threat Intelligence
Google operates the Google Threat Intelligence platform.
Google is related to Google Threat Intelligence Group
Google Threat Intelligence Group is a security group within Google.
Google is related to Threat Analysis Group
Threat Analysis Group is a security research team at Google.
Mandiant was acquired by Google
Mandiant was acquired by Google and integrated into Google Threat Intelligence Group.
Google Threat Intelligence Group is related to Threat Analysis Group
Google Threat Intelligence Group fuses tracking capabilities from Threat Analysis Group.
Google Threat Intelligence Group is related to Mandiant
Google Threat Intelligence Group fuses tracking capabilities from Mandiant.
Show 5 more connectionsShow fewer connections
Google Threat Intelligence is related to MITRE
Google Threat Intelligence platform preserves MITRE ATT&CK mappings.
Google Threat Intelligence Group is related to China
Tracks threat actors originating from China under CASTLE cryptonym.
Google Threat Intelligence Group is related to Russia
Tracks threat actors originating from Russia under RELIC cryptonym.
Google Threat Intelligence Group is related to Iran
Tracks threat actors originating from Iran under ION cryptonym.
Google Threat Intelligence Group is related to North Korea
Tracks threat actors originating from North Korea under NEPTUNE cryptonym.
Get the weekly recap
The stories like this one, picked and explained — once a week, straight to your inbox.