Google has a new way of talking about the latest cyber threats — so get ready for a whole load of crazy new names

Google has a new way of talking about the latest cyber threats — so get ready for a whole load of crazy new names | Daily Reports Online

Share


  • Google Threat Intelligence Group is replacing its inherited Mandiant and TAG identifiers with two-word cryptonyms, starting with several dozen of its most-tracked groups
  • The second word encodes attribution or motive, with CASTLE for China, ION for Iran, NEPTUNE for North Korea, RELIC for Russia, and COMET for criminal crews not visibly tied to a particular country
  • The scheme standardizes naming inside Google but adds another convention to an industry that agreed on a shared alias mapping only last year

The Russian military intelligence crew that most of the security industry knows as Sandworm has picked up another name – it is Sandworm Relic, at least when Google is doing the talking.


Google Threat Intelligence Group has announced plans to retire the tangle of identifiers it inherited from two separate teams and replacing them with two-word cryptonyms, starting with several dozen of the groups it tracks most closely and continuing on a rolling basis.


Similar Posts