← BACK TO FEED
cybersecuritythreat intelligenceGoogleMandiantthreat actors

Google Ditches the Industry Naming Pact and Builds Its Own Threat Actor Taxonomy

Google has launched its own two-word naming taxonomy for cybercrime groups, following its merger of Mandiant into the Google Threat Intelligence Group, assigning category terms such as CASTLE (China), RELIC (Russia), and COMET (non-state actors) as the second word. The move appears to contradict earlier reports that Google and Mandiant were open to joining a Microsoft and CrowdStrike-led industry initiative to standardise threat actor naming, which aimed to reduce the confusion caused by the same groups carrying up to ten different names across vendors. Google claims its system is intentionally simple to allow easy mapping to other taxonomies, though critics may see it as yet another competing schema adding to the existing fragmentation.

Google has quietly broken ranks with the rest of the cybersecurity industry and announced its own naming system for threat actors, apparently abandoning a Microsoft-led push to get everyone using the same terminology.

The announcement, made over the weekend, ties into Google's 2022 Mandiant acquisition. Now that Mandiant's threat intelligence operation has been folded into what Google calls the Google Threat Intelligence Group, the company says it needs a unified internal naming convention. Fair enough. What's less clear is why that means going it alone rather than joining the cross-industry effort already underway.

The schema itself is simple. Two words: the first is a unique identifier, either an existing nickname already used by the security community or a randomly generated term designed to avoid cultural bias. The second word acts as a category label reflecting the group's motivation, attribution, or primary activity type.

The category suffixes Google has landed on are: CASTLE for Chinese state-linked groups, ION for Iranian actors, NEPTUNE for North Korea, RELIC for Russia, and COMET for financially motivated criminals with no confirmed state backing.

Google acknowledges in its announcement that plenty of other naming schemes already exist, and says it deliberately kept things simple to make cross-referencing easier. That sounds reasonable until you remember that in early 2025, Microsoft and CrowdStrike were actively trying to get the industry to rally around a single shared taxonomy. At the time, sources indicated Google and Mandiant were interested in joining that effort.

This new announcement suggests that conversation went nowhere.

The underlying problem is real and genuinely annoying. The Russian military intelligence unit known to Western governments as Unit 74455 is also tracked under the names Seashell Blizzard, IRIDIUM, VOODOO BEAR, BE2, UAC-0113, Blue Echidna, PHANTOM, BlackEnergy Lite, and APT44, depending on which vendor's report you happen to be reading. Security teams using multiple tools regularly receive threat intelligence that refers to the same group by completely different names. Figuring out who is actually knocking on your door gets tedious fast.

On the bias question, Google's random name generation for new groups is a response to criticism from 2024, when China's National Computer Virus Emergency Response Center complained that Western security firms were using names like Typhoon, Panda, and Dragon to describe Chinese threat actors, framing it as culturally loaded. CVERC suggested neutral English-language terms like Hurricane or Koala would be preferable.

For what it's worth, Koala comes from the language of the Darug people, the indigenous Australians who lived around modern-day Sydney before British colonisation. And koalas, charming as they are, sleep between 18 and 22 hours a day. Naming an advanced persistent threat after an animal that is essentially comatose around the clock seems unlikely to sharpen anyone's incident response instincts. Though admittedly, the sleep schedule does describe certain strains of dormant malware with some accuracy.

READ NEXT
AI Hallucination Brands Startup as Chinese Spy Operation. No One Checked.Five Reasons Your Cybersecurity Strategy Is Already BehindRansomware Surges While Everyone's Busy Watching the AI Show