Google Threat Intelligence adopts unified threat actor naming system
Google Threat Intelligence Group (GTIG) is implementing a new, unified naming system for tracking threat actors, moving from historically separate schemas used by Mandiant and TAG. This cryptonym-based approach uses two-word combinations, with the second word categorizing actors by motivation or activity, aiming to provide defenders with better context and intuition for faster response. The system is being rolled out incrementally, with previous names remaining indexed and searchable on the GTI platform.
- →Unified threat actor naming system introduction
- →Cryptonym-based naming for threat actors
- →Simplified system to aid operations
- →Phased rollout and continued indexing
Enhancements (3) ›
- Cryptonym-based naming for threat actors
The new schema employs memorable two-word cryptonyms for each threat actor. The first word is a unique term representing the actor, and the second categorizes clusters by motivation, attribution, or activity type to aid defense and response strategies.
- Simplified system to aid operations
The naming system is designed to be simple and facilitate mapping to other taxonomies, acknowledging that direct comparisons between threat actors are rarely possible due to differing visibility among organizations.
- Phased rollout and continued indexing
Initially, dozens of the most active groups are being renamed, with the process continuing on a rolling basis. Previous names will remain indexed and searchable on the Google Threat Intelligence platform, preserving MITRE ATT&CK mappings and other vendor aliases.
Notes (1) ›
- Unified threat actor naming system introduction
Google Threat Intelligence Group is introducing a new, unified naming schema for tracking threat actors to standardize tracking across platforms and public reporting. This system aims to provide defenders with critical context for quicker operations.
https://cloud.google.com/blog/topics/threat-intelligence/updated-cyber-threat-actor-naming-system/
Related releases
- Cloud SDK 578.0.0: Database Migration default change, AlloyDB backup DR GA, BigQuery improvements Google Cloud release notes ·
- GKE: Opt-out of Arm taint, CORS for Gateways Google Cloud release notes ·
- Confidential VM: August 2026 kernel update may impact AMD SEV-SNP instances Google Cloud release notes ·
- Security Command Center ServiceNow Integration Updates Google Cloud release notes ·
- Compute Engine C4D Instances Increase Hyperdisk Throughput Google Cloud release notes ·
- Spanner allows creating tables without explicit primary keys Google Cloud release notes ·