Technology·

Google rolls out new naming system for cyber threat actors

Google rolls out new naming system for cyber threat actors

Defenders will see clearer attribution at a glance as Google Threat Intelligence Group replaces rival cyber-actor labels with two-word cryptonyms.

Google Threat Intelligence Group has begun rolling out a unified naming system for cyber threat actors, combining tracking methods previously used by Mandiant and Google's Threat Analysis Group. The new taxonomy assigns two-word cryptonyms to distinct threat actors, replacing separate naming approaches that developed independently before the teams were brought together under Google Threat Intelligence Group, or GTIG. Under the system, the first word is a unique, memorable term for a specific actor. It may reflect names already used in public reporting, while terms for newly identified groups may be randomly generated and then reviewed by analysts. The second word places the actor into a broader category based on motivation, attribution or activity type. Those categories are intended to give defenders a quicker indication of the kind of threat they are dealing with. Examples show category words tied to state-linked and criminal activity. Groups associated with the People's Republic of China will use CASTLE, Iran-linked actors ION, North Korea-linked actors NEPTUNE, Russia-linked actors RELIC and cybercriminal groups COMET. Why it changed The move follows the creation of GTIG, which combined cyber threat tracking work that had previously used parallel systems. The older model, which included sequential numbers and other identifiers, had become harder to use across platforms and in public reporting. As a result, analysts and customers were left with different labels for threat actors depending on which Google security team or historical reporting stream they were using. The new structure is intended to create a single reference point across the group's products and published intelligence. Google wanted a system that is easier to follow and closer to naming practices already used elsewhere in the cybersecurity industry. At the same time, it acknowledged that direct one-to-one comparisons between naming schemes remain difficult because organisations do not all have the same visibility into threat activity. Google is not attempting to rename every tracked group at once. The initial phase covers several dozen of the most active groups, with additional changes to follow on a rolling basis. Existing references Previous names will remain indexed and searchable in the Google Threat Intelligence platform. MITRE ATT&CK mappings and aliases used by other vendors will also be preserved, allowing analysts to cross-reference old and new identifiers during the transition. That matters because cyber threat intelligence work often depends on reconciling reporting from multiple companies, government agencies and security teams, many of which use their own naming methods for the same actor or cluster. Maintaining historical references reduces the risk that renamed groups become harder to track across earlier investigations and public records. Google is also keeping its UNC label for uncategorised threat clusters that are still at an early stage of investigation. Those designations are commonly used when analysts have identified suspicious activity or a possible actor grouping but have not yet gathered enough evidence to place it more firmly within an attribution or activity category. The adoption of cryptonyms reflects a broader problem in cybersecurity intelligence, where naming systems often emerge from internal research practices rather than a shared industry standard. As a result, one group can end up with several widely used names, while one name can sometimes refer to slightly different activity clusters depending on the organisation using it. By making the second word carry a category signal, Google is trying to attach a basic piece of operational context to each name rather than relying only on numbers or arbitrary labels. It argued that threat tracking should be easier to understand quickly, particularly for defenders working across large volumes of alerts, reports and investigations. Even so, Google made clear that the new system will not remove the underlying complexity of attribution. Different organisations still draw boundaries around threat clusters in different ways, based on what they can see and how they assess behaviour, infrastructure and links to previous campaigns. For users of the Google Threat Intelligence platform, the practical effect is likely to be a period in which old and new names appear side by side as the revised taxonomy expands. Previous names will remain indexed and searchable in the platform, with MITRE ATT&CK mappings and other vendor aliases preserved.

This is a summary. Read the full article at the original source.

Read full article at itbrief_com_au