Google threat actor taxonomy splits from Microsoft-backed naming push
Google introduced a new threat actor naming system after folding Mandiant into its intelligence unit, complicating a push for shared cybercrime labels.
By Renata Fuchs · Policy Reporter
· 3 min read
Google has introduced a new Google threat actor taxonomy, creating its own naming system for cybercrime and state-linked hacking groups after integrating Mandiant into the Google Threat Intelligence Group. The move matters for security teams because threat intelligence already arrives under competing vendor labels, and another major naming scheme may add work for analysts trying to match alerts across tools.
In a Saturday post, Google said the new system is meant to give its combined threat intelligence operation a consistent way to describe cybercrime crews. The company said the taxonomy uses two words: the first is a distinctive identifier for a specific actor, while the second describes the group’s motivation, suspected attribution or activity type, depending on what Google considers most useful for defense and response.
Google said it will keep existing names where security researchers already use them. When no accepted name exists, the company said it will generate a word at random to reduce bias in the label.
What is Google's new threat actor naming system?
The second word in Google’s taxonomy places threat clusters into broad categories. Google said it has chosen CASTLE for groups linked to the People’s Republic of China, ION for Iran-linked threats, NEPTUNE for North Korean attackers, RELIC for Russian groups and COMET for financially motivated or other criminal crews that are not state-backed.
That structure gives Google a short way to signal both an actor name and a high-level category. It also creates another mapping job for enterprises that consume intelligence from more than one security vendor, a common setup in large organizations.
Why cybercrime group names are hard to standardize
The security industry has long had a naming problem. Different vendors often track the same organization under different labels, which can obscure whether two reports describe separate crews or one actor seen through different telemetry.
One cited example is Russia’s Military Intelligence Unit 74455, which has been referred to by names including Seashell Blizzard, IRIDIUM, VOODOO BEAR, BE2, UAC-0113, Blue Echidna, PHANTOM, BlackEnergy Lite and APT44. For defenders, that fragmentation can turn a threat report into a translation exercise before response work begins.
Google acknowledged that other security companies have developed their own naming systems and said it is trying to keep its version simple so it can be mapped to other taxonomies. That positioning sits uneasily with a Microsoft and CrowdStrike-backed effort in 2025 to push the industry toward more consistent threat actor names.
Google’s announcement does not say that it is adopting that Microsoft-led scheme. It instead lays out a Google-specific approach built around the combined Mandiant and Google threat intelligence operation.
Bias concerns are part of the naming fight
Google’s reference to random generation also lands in a debate over cultural framing in cyber labels. In 2024, China’s National Computer Virus Emergency Response Center criticized Western companies for using terms such as “Typhoon,” “Panda” and “Dragon” for Chinese hacking groups.
The Chinese agency suggested names tied to English-language idioms, including “Hurricane” or “Koala,” as alternatives. Google’s stated plan to randomize names where no established label exists appears aimed at avoiding some of those disputes, although the company still assigns country-linked category words such as CASTLE, ION, NEPTUNE and RELIC.
For buyers and operators, the practical issue is less the branding than the mapping. If Google’s system becomes another parallel taxonomy rather than a bridge among existing ones, security teams will have one more reference table to maintain when they compare vendor reports, SIEM alerts and incident response notes.
This story draws on original reporting from The Register.