TechNewsReel
Live

Google Replaces APT Numbers With Country-Coded Hacking Group Names

The cybersecurity giant is unifying its Threat Analysis Group and Mandiant naming schemes to better track over 5,000 activity clusters.

TechNewsReel Newsroom · August 8, 2026

Google has overhauled its naming convention for hacking groups to unify the disparate schemes used by its Threat Analysis Group (TAG) and Mandiant. The move replaces the legacy "APT" (Advanced Persistent Threat) numbering system with a two-word format designed to provide immediate clarity on an actor's origin.

Under the new system, each group is assigned a random, memorable first name paired with a second word whose initial identifies the country of origin. The specific identifiers include "Castle" for China, "Ion" for Iran, "Neptune" for North Korea, and "Relic" for Russia. This structural change comes as Google now tracks more than 5,000 distinct "activity clusters" across multiple nations.

The Chaos of Cyber Codenames

For more than a decade, the cybersecurity industry has struggled with a fragmented identity system for threat actors. Groups often carry multiple aliases—such as Fancy Bear or the Lazarus Group—depending on which security firm is tracking them. Because different vendors rely on their own proprietary telemetry and data, the industry has historically depended on aggregators like MITRE ATT&CK to map these various identities to a single entity.

Shane Huntley, CTO of Google Threat Intelligence Group, noted that the sheer volume of actors has outpaced original expectations, stating, "we were not expecting to have as many threat groups as we do today." This growth has made the old numbering systems cumbersome and less intuitive for researchers.

Streamlining Incident Response

Consistent naming is an operational necessity for incident response. When a security team can quickly identify a specific actor, they can immediately leverage known data regarding that actor's past behaviors, preferred tools, and strategic goals. This allows organizations to recognize threats faster and tighten their defensive coverage against specific state-sponsored tactics.

By unifying its internal naming, Google aims to reduce the cognitive load on its researchers and streamline the process of identifying threats. The shift from abstract numbers to country-coded names allows responders to instantly categorize the geopolitical context of an intrusion.

The Limits of Visibility

Despite the new system, Google acknowledges that tracking state-sponsored actors remains an imperfect science. The ability to attribute a hack to a specific group is based on the best available evidence rather than absolute certainty.

"No one has perfect visibility," Huntley told TechCrunch. "We are building our model and our best understanding, but we will never know everything about what’s going on." As Google continues to monitor thousands of clusters, the industry will be watching to see if other major security vendors adopt similar intuitive naming conventions to reduce global fragmentation.

Sources

Get a notification when a big story breaks. A few a day at most — no spam.