Google Introduces Unified Cryptonym-Based Threat Actor Naming System

Google Introduces Unified Cryptonym-Based Threat Actor Naming System

First seen 25 Jul 2026, 21:39 UTC Cloud.GoogleGbhackers 75% similarity 18.8

Article Content

Browse articles
ThreatCluster

On July 24, 2026, Google Threat Intelligence Group (GTIG) rolled out a new unified naming system for cyber threat actors. This system aims to standardize tracking across platforms and improve clarity in threat attribution. The new naming convention employs memorable two-word cryptonyms, with the first word representing the actor and the second categorizing by motivation or activity type. This initiative follows the merger of Mandiant and Google’s Threat Analysis Group, which previously used distinct tracking systems. The new system is designed to simplify operations and facilitate mapping to existing naming taxonomies. GTIG will prioritize renaming several dozen of the most active threat groups, with the names indexed in the Google Threat Intelligence platform. The transition aims to enhance the speed and effectiveness of threat response for cybersecurity professionals.

Key Points: • Google's new naming system uses memorable two-word cryptonyms for threat actors. • The initiative aims to standardize tracking and improve clarity in threat attribution. • GTIG will prioritize renaming several dozen active threat groups in the initial rollout.

ThreatCluster AI

Timeline

2026-07-24
Launch of unified cryptonym-based naming system
Google Threat Intelligence Group introduced a new naming convention for tracking cyber threat actors, aiming to simplify attribution and improve analyst workflows.
Cloud.Google
2026-07-24
Integration of Mandiant and TAG into GTIG
The merger of Mandiant and Google’s Threat Analysis Group necessitated a new unified naming system for threat actors.
Gbhackers

Community

Browse all →