Google Breaks Ranks With Proprietary Threat Actor Naming System
GTIG's two-word cryptonym taxonomy departs from 2025 industry standardization effort led by Microsoft and CrowdStrike.
Google's Threat Intelligence Group (GTIG) has unveiled its own threat actor naming taxonomy, abandoning a 2025 industry-wide standardization effort in favor of a proprietary two-word cryptonym system.
A New Naming Convention
The new schema replaces the separate tracking systems previously maintained by Mandiant and Google's Threat Analysis Group (TAG) following their integration into GTIG. Each threat actor receives a two-word identifier: the first word serves as a unique name, while the second categorizes the group by origin or motivation.
Google's category keywords map to specific nations and actor types: CASTLE for China-affiliated groups, ION for Iran, NEPTUNE for North Korea, RELIC for Russia, and COMET for cybercriminals regardless of country or origin.
"Threat tracking shouldn't be an exercise in memorization, but rather one of intuition," GTIG wrote in a blog post announcing the change.
Breaking From Industry Consensus
The move marks a significant departure from collaborative efforts announced in June 2025, when Microsoft and CrowdStrike led an initiative to standardize threat actor naming across the cybersecurity sector. Records confirm that Google and Mandiant initially participated in that effort before pivoting to develop their own system.
The Register characterized the decision as Google "going it alone" on threat taxonomy.
The Naming Fatigue Problem
Google's intervention addresses a long-standing problem in cybersecurity: "naming fatigue," where a single threat actor accumulates multiple aliases across different vendor reports. Industry observers note that Google's decision appears to prioritize internal operational efficiency and bias reduction over industry-wide interoperability.
What This Means for Defenders
The practical impact remains unclear. While GTIG's system may streamline internal tracking and reduce vendor-specific bias in threat attribution, it adds another taxonomy to an already crowded field. Security teams consuming intelligence from multiple vendors will now need to maintain crosswalks between Google's cryptonyms, Microsoft's conventions, and legacy naming schemes from other providers.
The fragmentation could prolong the very confusion the 2025 standardization effort aimed to resolve, though Google's market position may encourage broader adoption of its system over time.