GOOGLE Threat Intelligence Group (GTIG) is transitioning to a new cryptonym-based naming convention for identifying threat actors. This method replaces sequential identifiers with memorable two-word combinations: the first word represents the threat actor, while the second categorizes them by motivation or origin. For example, Chinese actors will use 'Castle' while North Korean groups will use 'Neptune'. Google’s notorious ‘APT44’ will now be referred to as 'Sandworm Relic'.
This change aims to simplify actor tracking and enhance clarity across cybersecurity organizations. Although previous names will still be searchable, this ongoing transition seeks to provide a more straightforward and cohesive understanding of threat actors.