For over ten years, cybersecurity teams have given catchy codenames to dangerous hacking groups. Names like Fancy Bear made headlines around the world after high-profile cyberattacks, while other obscure names stay buried inside private security reports. Keeping track of these digital threat groups has become a massive headache, even for seasoned industry professionals. Part of the confusion stems from the fact that every major cybersecurity firm invents its own distinct naming system for the same bad actors.
Google recently decided to overhaul its internal system for tagging hacker groups. In the past, companies relied on cold numbers like APT1 or APT41, a system originally created by Mandiant before Google acquired the firm. That old numerical scheme is officially gone. Google replaced it with a cleaner two-word naming structure designed to bring order to the chaos.
Under the new blueprint, every tracked hacking group gets a memorable, random first name paired with a second word that reveals its country of origin. Hacking outfits tied to China receive the second word Castle, while Iranian groups get the tag Ion. North Korean state hackers carry the name Neptune, and Russian cyber crews get tagged with Relic.
Shane Huntley, chief technology officer at Google Threat Intelligence Group, explained that this update brings needed clarity to security researchers tracking digital threats across the globe. When security teams began publishing threat reports back in the early 2010s, nobody anticipated the sheer volume of hacking groups operating today. Google currently tracks more than 5,000 separate activity clusters around the world. John Hultquist, chief analyst at Google Threat Intelligence Group, noted that nearly every developed nation on Earth now operates its own active state hacking units.
Assigning clear codenames to these groups is far more than an academic exercise. Naming hackers creates a shared baseline for understanding who launches attacks, what tools they deploy, and which targets they pursue. When defenders identify a threat quickly, they can build better defenses, stop active intrusions, or conduct faster forensic investigations.
Knowing how specific groups operate gives security teams a massive advantage. For example, tracking the famous North Korean outfit known as the Lazarus Group allows defenders to anticipate their goals, recognize their malware signatures, and block their usual attack vectors.
Huntley pointed out that tracking government-backed cyber spies is actually easier than tracking standard criminal gangs or commercial hackers-for-hire. State-sponsored hackers follow consistent goals, target specific industries, and maintain organized squad structures. In contrast, basic cybercrime syndicates constantly split apart, swap members, and change their methods. Commercial spyware makers sell their tools to dozens of different buyers around the globe, making their operational footprints much harder to follow.
People often ask why every security company cannot simply agree on one single naming system. The reality is that each cybersecurity firm sees the digital landscape through its own unique telemetry and dataset. No single company possesses complete visibility across the entire internet. Because each firm gathers different data, their threat models differ slightly. Google combined its Threat Analysis Group with Mandiant to eliminate at least one redundant system, giving security researchers one less naming scheme to worry about as they defend networks worldwide.

