Cloud.Google
Google Introduces Unified Cryptonym-Based Threat Actor Naming System
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
On July 24, 2026, Google Threat Intelligence Group (GTIG) rolled out a new unified naming system for cyber threat actors. This system aims to standardize tracking across platforms and improve clarity in threat attribution. The new naming convention employs memorable two-word cryptonyms, with the first word representing the actor and the second categorizing by motivation or activity type. This initiative follows the merger of Mandiant and Google’s Threat Analysis Group, which previously used distinct tracking systems. The new system is designed to simplify operations and facilitate mapping to existing naming taxonomies. GTIG will prioritize renaming several dozen of the most active threat groups, with the names indexed in the Google Threat Intelligence platform. The transition aims to enhance the speed and effectiveness of threat response for cybersecurity professionals.
Key Points: • Google's new naming system uses memorable two-word cryptonyms for threat actors. • The initiative aims to standardize tracking and improve clarity in threat attribution. • GTIG will prioritize renaming several dozen active threat groups in the initial rollout.