Google Overhauls Hacker Group Naming System with Country Codes
TechNadu · x · 2026-08-10
Google's Threat Intelligence team has revamped its naming system for hacking groups, moving away from the traditional APT numbering scheme used by Mandiant.
The new system uses memorable names where the second word's initial indicates the assessed country of origin (e.g., Castle for China, Ion for Iran, Neptune for North Korea, Relic for Russia). Google's Threat Intel CTO noted that while Google now tracks over 5,000 threat clusters, a universal naming system across the industry remains impossible because security vendors have different telemetry and visibility during real incidents.
More from Safety
- Debating OpenAI/HF Incident: Weaker Monitors Still Need Chain-of-Thought — ArthurConmy · 2026-08-10
- BGA Framework: Detecting Malicious Commands in Encrypted Traffic — 量子位 · 2026-08-10
- AI Replacing 1,000 Workers Exposes the Absurdity of Current Machine Tax Policies — VraserX · 2026-08-10
- NeurIPS Reviewer Complains: Most Papers Are Now AI-Generated Slop — HildeKuehne · 2026-08-10
- Raptor: Open-source project turns Claude Code into autonomous security agent — tom_doerr · 2026-08-10
- Stanford Scholar Highlights Fragile Foundations of CoT Monitoring Against Attacks — stanfordnlp · 2026-08-10