Google’s top hacker hunter explains why hacking groups get code names
- ID
- 12223
- Status
- summarized
- Published
- 08 Aug 2026, 11:00 PM
- Fetched
- 11 Aug 2026, 1:39 AM
- Provider
- TechCrunch
- Category
- technology
- Original URL
- https://techcrunch.com/2026/08/08/googles-top-hacker-hunter-explains-why-hacking-groups-get-codenames/
- Source URL
- https://techcrunch.com/feed/
Summary
- Score
- 3.0
- Created
- 11 Aug 2026, 1:41 AM
- Tags
- Audience
- developers
What happened
Google's Threat Intelligence Group (formerly Mandiant) has retired its APT-numbering system for naming hacking groups in favor of a two-word scheme: a memorable random first name plus a second word whose initial signals country of origin (Castle for China, Ion for Iran, Neptune for North Korea, Relic for Russia). CTO Shane Huntley said the change was needed because Google now tracks over 5,000 activity clusters, far more than the early 2010s when naming began.
Why it matters
If your team consumes Google/Mandiant threat intelligence reports or feeds, expect group names to shift from APT-style identifiers to the new naming convention—update any internal references, dashboards, or alert rules that match on threat actor names. For most builders not in security operations, this is informational only.
Discussion angle
Whether vendor-specific naming taxonomies for 5,000+ threat actors actually help defenders or just create lock-in to one company's taxonomy.