---
title: "From APT1 to Castle and Neptune: Google Launches New Naming System for Hacker Groups"
description: "🚨 Google has updated the naming system for hacker groups. Instead of boring APT1 and APT28, memorable names indicating the country of origin are now used. 🇨🇳 Chinese hackers are now \"Castle\". 🇰🇵 North Korea — \"Neptune\". 🇮🇷 Iran — \"Ion\". The new system is designed to simplify the work of cybersecurity specialists in conditions where Google tracks more than 5,000 threat clusters. 🛡️ #Google #CyberSecurity #Hacking #TechNews"
date: 2026-08-09T13:31:34.000Z
lang: en
url: https://xab.info/en/posts/google-new-naming-system-for-hacker-groups-castle-neptune
tags: [google, cybersecurity, apt-groups, mandiant, tech-news, hacking]
publisher: "XAB.info"
---

# From APT1 to Castle and Neptune: Google Launches New Naming System for Hacker Groups

![Google logo on the building facade, symbolizing the new naming system for hacker groups](https://xab.info/media/2026/08/09/google-novaya-sistema-imenovaniya-hakerskih-grupp-castle-neptune/google-novaya-sistema-imenovaniya-hakerskih-grupp-castle-neptune-1.webp)

## 🎯 Key Points

- Google abandoned APT numbering in favor of names indicating the country of origin of hackers.
- The new system combines Google TAG and Mandiant approaches to simplify threat analysis.
- The company tracks more than 5,000 activity clusters, making the old system ineffective.
- Full unification of naming between different companies remains impossible due to differences in data.

In August 2026, Google announced a major reform in the field of cybersecurity, affecting the fundamental principles of identifying digital threats. The company abandoned the outdated numbering system (APT1, APT28, etc.) in favor of a new, more intuitive and memorable system of code names. This decision, made by the Google Threat Analysis Group, is designed to simplify the work of security specialists and accelerate the response to incidents in the face of an explosive growth in the number of cyber threats.

### From Numbers to Code Names: The Logic of the New System

The new methodology, reported by TechCrunch, combines the approaches of the Google Threat Analysis Group and Mandiant (acquired by Google in 2022). Previously, specialists relied on abstract designations that eventually became inconvenient due to their sheer number. Shane Huntley, Technical Director of the Google Threat Intelligence Group, explained that in the early 2010s, when reports on cyberattacks were just beginning to be published, no one expected that the number of tracked groups would reach five thousand activity clusters.

The system has a strict structure: the first word in the name is chosen randomly for ease of memorization, while the second word indicates the country of origin of the group. For example, for groups from China, the prefix **Castle** is used; for Iran — **Ion**; and for North Korea — **Neptune**. This approach allows researchers to instantly determine the geographic vector of the threat and link current activity to historical data on the methods of a specific actor.

### Practical Benefits for Infrastructure Protection

As Huntley notes, the goal of the innovation goes beyond simple convenience for analysts. Understanding the "profile" of the attacker — their goals, tactics, and past actions — is critical for organizations that have faced an attack. "If you are actually hacked, knowing how the attacker behaves and what they did in the past becomes key to responding and planning protection," the expert emphasized. A unified naming system within the Google ecosystem allows for faster use of accumulated data for incident investigation and building effective protection.

### Contradictory Data and Unification Challenges

Despite the drive for standardization, experts point out objective difficulties in attempting to create a single global naming system. Full unification between different companies is practically impossible, as specialists receive different sets of data and telemetry from remote nodes. This leads to the fact that the same activity may be assessed and classified differently by various vendors.

Furthermore, there is a difference in the trackability of different types of threats. State-sponsored hacker groups are generally easier to identify due to the stability of their goals and methods. At the same time, cybercriminals and mercenary groups are significantly harder to classify: they often change their composition, split into new groups, and serve different clients, which blurs the clear boundaries for their identification.

## 🔍 Fact-Check Verification

- [Google’s top hacker hunter explains why hacking groups get codenames](https://www.msn.com/en-us/money/other/google-s-top-hacker-hunter-explains-why-hacking-groups-get-codenames/ar-AA29EoeV) - Подтверждает цитаты Шейна Хантли и логику перехода на новую систему.
- [Google Unveils Secret Code Names for Hackers: CASTLE for China Hackers, RELIC for Russia and NEPTUNE for North Korea](https://www.ibtimes.sg/google-unveils-secret-code-names-hackers-castle-china-hackers-relic-russia-neptune-north-90661) - Подтверждает конкретные примеры названий (Castle, Neptune, Ion) и их привязку к странам.
- [Google unifies names for tracked cyber threat groups](https://www.msn.com/en-ae/news/other/google-unifies-names-for-tracked-cyber-threat-groups/ar-AA28KUje) - Подтверждает цитаты Шейна Хантли и логику перехода на новую систему.

## ❓ FAQ

### Q: Why did Google change the naming system for hacker groups?
**A:** The old numbering system (APT1, APT28) could no longer cope with the growth in the number of threats. Google now tracks more than 5,000 activity clusters, and the new names help identify threats faster.

### Q: How are the new group names decoded?
**A:** The first word is random and memorable; the second indicates the country. For example, 'Castle' — China, 'Neptune' — North Korea, 'Ion' — Iran.

### Q: Will this system be unified for all companies?
**A:** No, full unification is impossible due to differences in data and telemetry used by different cybersecurity companies.