Key Takeaways
- Google Threat Intelligence Group is introducing a unified taxonomy for identifying and tracking major cyber threat groups.
- The system uses category-based labels while preserving historical vendor aliases and temporary UNC designations.
- Adoption beyond Google will determine whether the taxonomy reduces confusion across security operations and incident reporting.
Google is rolling out a standardized naming system intended to make cyber threat actors easier to identify across intelligence reports, security products and incident investigations. The initiative addresses a persistent industry headache: one malicious group can have several names, depending on which research team discovered or documented its activity.
The Google Threat Intelligence Group taxonomy creates common identifiers while retaining historical aliases and legacy tags. That distinction matters. Google is not asking defenders to discard years of reporting from Mandiant, CrowdStrike, Microsoft or other researchers. Instead, the system is designed to provide a common reference layer that can map those established labels to a consistent public name.
In practice, this resembles the way scientific classifications create stable references for species that may have different regional names. Cyber attribution is far less tidy, of course. Threat groups split, share infrastructure, change malware and sometimes imitate one another, so any naming system has to accommodate uncertainty rather than present attribution as settled fact.
Google’s approach combines two-word cryptonyms with category-based suffixes that communicate an assessed geographic association or motivation. According to CyberScoop, the categories include Castle for activity associated with China, ION for Iran, Neptune for North Korea and Relic for Russia. Financially motivated actors also receive a distinct category.
Those labels are intended as neutral analytical references, not political declarations. Even so, attribution language carries weight. A memorable cryptonym can quickly move from a technical report into executive briefings, government statements and media coverage. Security teams will still need to distinguish between observed technical evidence, a vendor’s assessment and formal attribution by a government.
Naming confusion is more than an editorial inconvenience. During an active incident, analysts may need to compare indicators, malware families and tactics across reports from several providers. If each report uses a different actor name, responders can lose time determining whether they are examining one cluster, related clusters or entirely separate operations.
A shared taxonomy can help reduce that translation burden. It may also improve automation in threat-intelligence platforms, where aliases frequently need to be mapped manually or maintained in reference tables. For security operations centers, cleaner mappings can support more consistent alert enrichment, case management and executive reporting.
The transition will not happen all at once. Early-stage activity clusters will continue to receive temporary UNC, or uncategorized threat actor, designations until researchers have enough evidence to map the activity more confidently. That preserves an important feature of the Mandiant research model: analysts can track related behavior without prematurely claiming that it belongs to a known organization.
The nomenclature also complements, rather than replaces, MITRE ATT&CK. The D3fD3c0y threat-actor naming reference illustrates how widely vendor conventions can diverge, while MITRE ATT&CK gives defenders a comparatively stable way to describe adversary techniques and procedures. Names answer who researchers think they are observing. Behavioral mappings describe what the actor did. Incident responders usually need both.
Will the rest of the industry adopt Google’s labels? That remains the practical test. CrowdStrike, Microsoft and other intelligence providers have developed recognizable naming systems tied to their own research methods, data and confidence thresholds. They may map Google’s identifiers without abandoning their internal terminology, producing interoperability rather than full uniformity.
That said, interoperability alone would be useful. A common reference system could make vendor reports easier to compare, improve intelligence sharing between businesses and governments, and reduce ambiguity in board-level discussions. It will not settle disputed attribution or eliminate duplicate clusters. But if Google can persuade researchers and security platforms to maintain reliable cross-references, the industry may gain something it has lacked for years: a clearer shared vocabulary for discussing the same adversaries.
⬇️