Skip to content
Google Introduces Unified Cryptonym-Based Threat Actor Naming System

Google Introduces Unified Cryptonym-Based Threat Actor Naming System

First seen 25 Jul 2026, 21:39 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster July 26, 2026 at 20:35 UTC
  • Google's new naming system uses memorable two-word cryptonyms for threat actors.
  • The initiative aims to standardize tracking and improve clarity in threat attribution.
  • GTIG will prioritize renaming several dozen active threat groups in the initial rollout.

On July 24, 2026, Google Threat Intelligence Group (GTIG) rolled out a new unified naming system for cyber threat actors. This system aims to standardize tracking across platforms and improve clarity in threat attribution. The new naming convention employs memorable two-word cryptonyms, with the first word representing the actor and the second categorizing by motivation or activity type. This initiative follows the merger of Mandiant and Google’s Threat Analysis Group, which previously used distinct tracking systems. The new system is designed to simplify operations and facilitate mapping to existing naming taxonomies. GTIG will prioritize renaming several dozen of the most active threat groups, with the names indexed in the Google Threat Intelligence platform. The transition aims to enhance the speed and effectiveness of threat response for cybersecurity professionals.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 46d ago How this analysis works

Timeline

2026-07-24
Launch of unified cryptonym-based naming system
Google Threat Intelligence Group introduced a new naming convention for tracking cyber threat actors, aiming to simplify attribution and improve analyst workflows.
Cloud.Google
2026-07-24
Integration of Mandiant and TAG into GTIG
The merger of Mandiant and Google’s Threat Analysis Group necessitated a new unified naming system for threat actors.
Gbhackers

More articles in this cluster (15)

Following this threat?

Track APT1 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed