New Names for Cybercriminals

Google Cleans Up Its Hacker Naming System

Hacker, Google Threat Intelligence, Google Threat Intelligence threat actor naming system, Google new names for hacker groups, hacker groups, Mandiant, MITRE ATT&CK, Google, Cybercriminals
Facebook
X
LinkedIn
Reddit
WhatsApp
Source: Shutterstock.com/Google

The Google Threat Intelligence Group is overhauling its tracking system for cyber threat actors. Instead of cryptic abbreviations such as APT41, the group will use two part codenames to make threat tracking easier to navigate.

Google has announced a major overhaul of its system for naming hacker groups. The Google Threat Intelligence Group (GTIG), which brings together security firm Mandiant and Google’s in house Threat Analysis Group (TAG), is introducing a unified cryptonym based naming scheme. According to the company, the rollout is already underway.

Ad

Two Separate Systems Are Being Merged

Until now, Mandiant and TAG each maintained their own systems for categorizing threat actors, which had evolved independently over the years. Following the merger of the two teams under GTIG, Google says a shared naming system became necessary.

Google argues that sequential numbering and inconsistent abbreviations such as “APT1” do not provide defenders with enough context to respond quickly when an attack is underway. The company is therefore aligning its approach with naming conventions already used across the cybersecurity industry.

Going forward, GTIG will use cryptonyms for threat actors. Sequential numbers and inconsistent labels such as “APT1” do not give defenders the context they need to act quickly. Threat tracking should not be a matter of memorization, but rather of intuition. The new naming convention is designed to align with industry standard threat actor naming systems.

Ad

Google Threat Intelligence Group

How the New Naming Scheme Works

Each threat group will receive a two word name:

  1. The first word is a memorable, unique term assigned to the group. If a name is already widely used publicly, Google will adopt it. Otherwise, the term will be generated at random and then reviewed by analysts to reduce the risk of bias.
  2. The second word places the group into a category based on its motivation, origin or type of activity, depending on which aspect is considered most relevant for defense strategies.

These category terms effectively serve as a surname for entire groups of threat actors. Google gives the following examples in its announcement:

Origin/TypeCategory Name
People’s Republic of ChinaCASTLE
IranION
North KoreaNEPTUNE
RussiaRELIC
CybercriminalsCOMET

For example, a Chinese threat group could be called “Redcastle” under the new system, while a North Korean group might appear under a name that includes the “Neptune” suffix.

Comparability Remains Limited

Google itself acknowledges that the cybersecurity industry already uses several parallel tracking systems, including those maintained by CrowdStrike, Microsoft and MITRE. The new scheme is deliberately designed to be simple, making it easier to map Google’s names to naming conventions used by other security vendors. However, a direct, one to one comparison between vendors will remain difficult because no provider has exactly the same view of the threat landscape. Google therefore sees the change primarily as a pragmatic step to make its own threat tracking more manageable, rather than as a solution to the industry’s broader naming inconsistencies.

Old Names Will Remain Available

The transition will take place gradually. Google will initially rename several dozen of the most active groups, with more to follow on an ongoing basis. Previous names, along with their mappings to the MITRE ATT&CK framework and aliases used by other vendors, will remain available and searchable on the Google Threat Intelligence (GTI) platform. For threat clusters that are still in the early stages of investigation, Google will continue to use the designation “UNC,” short for “uncategorized.”

(lb)

Ad

Artikel zu diesem Thema

Weitere Artikel