logo

Google Launches Unified Cryptonym-Based Naming System for Threat Actors

ID: 216b2d0c-6b0d-5b1f-bee5-767f25cb5917

STIX ID: report--216b2d0c-6b0d-5b1f-bee5-767f25cb5917

Feed Name: GBHackers

Threat Score
30/100

Date Published: 2026-07-25

Date Updated: 2026-07-25

Author: Eswar

...
...

GTIG has launched a unified, two-word cryptonym naming scheme to standardize threat actor identifiers across Google’s security teams, retaining recognizable identifiers where possible and appending a category word (e.g., RELIC for Russia) to convey attribution; Sandworm (APT44) is cited as being renamed to SANDWORM RELIC. The framework preserves legacy aliases and ATT&CK mappings to aid continuity, and organizations are advised to update internal references and detection content as the new cryptonyms propagate.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.