In August 2026, Google announced a major reform in the field of cybersecurity, affecting the fundamental principles of identifying digital threats. The company abandoned the outdated numbering system (APT1, APT28, etc.) in favor of a new, more intuitive and memorable system of code names. This decision, made by the Google Threat Analysis Group, is designed to simplify the work of security specialists and accelerate the response to incidents in the face of an explosive growth in the number of cyber threats.
From Numbers to Code Names: The Logic of the New System
The new methodology, reported by TechCrunch, combines the approaches of the Google Threat Analysis Group and Mandiant (acquired by Google in 2022). Previously, specialists relied on abstract designations that eventually became inconvenient due to their sheer number. Shane Huntley, Technical Director of the Google Threat Intelligence Group, explained that in the early 2010s, when reports on cyberattacks were just beginning to be published, no one expected that the number of tracked groups would reach five thousand activity clusters.
The system has a strict structure: the first word in the name is chosen randomly for ease of memorization, while the second word indicates the country of origin of the group. For example, for groups from China, the prefix Castle is used; for Iran — Ion; and for North Korea — Neptune. This approach allows researchers to instantly determine the geographic vector of the threat and link current activity to historical data on the methods of a specific actor.
Practical Benefits for Infrastructure Protection
As Huntley notes, the goal of the innovation goes beyond simple convenience for analysts. Understanding the "profile" of the attacker — their goals, tactics, and past actions — is critical for organizations that have faced an attack. "If you are actually hacked, knowing how the attacker behaves and what they did in the past becomes key to responding and planning protection," the expert emphasized. A unified naming system within the Google ecosystem allows for faster use of accumulated data for incident investigation and building effective protection.
Contradictory Data and Unification Challenges
Despite the drive for standardization, experts point out objective difficulties in attempting to create a single global naming system. Full unification between different companies is practically impossible, as specialists receive different sets of data and telemetry from remote nodes. This leads to the fact that the same activity may be assessed and classified differently by various vendors.
Furthermore, there is a difference in the trackability of different types of threats. State-sponsored hacker groups are generally easier to identify due to the stability of their goals and methods. At the same time, cybercriminals and mercenary groups are significantly harder to classify: they often change their composition, split into new groups, and serve different clients, which blurs the clear boundaries for their identification.