- Google tracks 5,000+ cyber “activity clusters” globally.
- Old labels such as APT1/APT41 are being replaced.
- New format: memorable random first name + country-coded second name.
- Castle → China
- Ion → Iran
- Neptune → North Korea
- Relic → Russia
- Purpose: identify, track and understand threat actors faster.
- Consistent naming helps defenders analyse an attacker’s past behaviour, targets and tactics.
- State-sponsored groups are generally easier to track than cybercriminal and hacker-for-hire groups.
- Different cybersecurity firms use different names because they have different data and visibility.
- Google says no organisation has perfect visibility into the cyber threat landscape.
- Example: Tracking the Lazarus Group helps defenders understand its behaviour, goals and affiliations.
- Bottom line: Naming hackers isn’t branding—it helps defenders recognise, investigate and respond to threats faster.
Reference: TC






