For over a decade, the cybersecurity industry has relied on codenames to track hacking groups, though the practice has become fragmented as different security firms use conflicting names. To bring much-needed clarity, Google has rolled out a revamped and simplified naming system for these threat actors.
Under the updated framework, each hacking group receives a memorable, random first name followed by a second word indicating its country of origin, such as China, Iran, North Korea, or Russia. With Google tracking over 5,000 distinct activity clusters globally, consistent naming and tracking are essential for organizations to quickly recognize, investigate, and mitigate cyberattacks.
- Google updated its naming convention for state-sponsored and cybercrime hacking groups.
- The new system uses a random first name and a country-indicating second word.
- Google currently monitors more than 5,000 distinct threat activity clusters.
- Consistent tracking and naming improve threat intelligence and incident response.
Sources:
