logo

Google changes how it names cyber threat actors

ID: fd67b7de-b8b4-54d7-924b-3f4250d4919b

STIX ID: report--fd67b7de-b8b4-54d7-924b-3f4250d4919b

Feed Name: Help Net Security

Date Published: 2026-07-27

Date Updated: 2026-07-28

Author: Sinisa Markovic

...
...

Google Threat Intelligence Group (GTIG) has implemented a simplified two-word naming system for tracked threat actors following a merger with Mandiant: the first word preserves existing public names or is randomly generated, and the second word denotes category/attribution (e.g., CASTLE for China, ION for Iran, NEPTUNE for North Korea, RELIC for Russia, COMET for cybercrime); existing names and mappings (including MITRE ATT&CK) remain searchable and UNC is retained for uncategorized clusters.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.