Google Threat Intelligence Group (GTIG) has announced a new naming convention for the threat actors it tracks, moving away from sequential numeric identifiers like “APT44” toward a two-word cryptonym system designed to be easier to remember and communicate across the industry.
Under the new schema, each activity cluster gets a unique first word that may already exist in public reporting, or a randomly generated term if no established name is available. The second word places the actor into a category based on motivation, attribution, or activity type. Google has assigned specific category terms to different origins: “Castle” for China-linked groups, “Ion” for Iranian actors, “Neptune” for North Korean groups, “Relic” for Russian threat actors, and “Comet” for cybercrime gangs.
Sandworm Becomes the First High-Profile Rename
The most notable example is Russia’s Sandworm group, previously tracked by Google as APT44, which will now be designated “Sandworm Relic.” The group carries a long list of aliases across the security community, including Blue Echidna, Electrum, FrozenBarents, G0034, Iridium, Iron Viking, Quedagh, Seashell Blizzard, TEMP.Noble, TeleBots, UAC-0082, UAC-0113, and Voodoo Bear, underscoring the fragmentation the new system is meant to help address.
Google says it intentionally kept the schema simple to streamline internal operations and to make mapping to other vendors’ naming taxonomies easier. The company acknowledged that differing visibility into the threat landscape across organizations still prevents direct, apples-to-apples comparisons between tracked actors in most cases, but framed the new convention as a practical step toward managing that complexity.
Rollout and Backward Compatibility
Google has already renamed several dozen of its most active tracked threat actors as part of the initial transition, with the process continuing on a rolling basis going forward. Previous designations will remain indexed and searchable within the Google Threat Intelligence (GTI) platform, alongside preserved MITRE ATT&CK mappings and known vendor aliases, so analysts relying on legacy names should not lose that context.
Uncategorized threat clusters that Google has not yet attributed to a specific motivation or origin will continue to use the existing UNC designation format.
The move follows broader industry efforts to reduce confusion caused by overlapping threat actor naming schemes, including a Microsoft and CrowdStrike-led initiative to map aliases across vendors and Microsoft’s own switch to naming actors after weather events.
