Google Threat Intelligence Group (GTIG) announced on July 23, 2026, that it is rolling out a single, unified naming schema for threat actors, merging the previously separate tracking systems used by Mandiant and Google’s Threat Analysis Group (TAG) into one cryptonym-based taxonomy.
For years, Mandiant and TAG operated parallel tracking systems that grew independently, producing overlapping and sometimes contradictory identifiers for the same threat clusters.
GTIG’s formation made a fused system necessary, and Google concluded that sequential identifiers like “APT1” burden defenders with memorization rather than intuition, slowing response during active incidents. The new approach is designed to align with how the rest of the industry already labels adversaries, easing cross-vendor correlation.
Google GTIG Unifies Cyber Threat Actor Naming
Each threat actor now receives a memorable two-word cryptonym. The first word is a unique identifier, often carried over from prior public reporting when one already exists, or randomly generated and analyst-vetted when it doesn’t, to avoid unconscious bias in naming.
The second word signals the category Google considers most operationally relevant for that actor, whether that’s national origin, motivation, or activity type.
| Origin/Type | Cryptonym Suffix |
|---|---|
| People’s Republic of China | CASTLE |
| Iran | ION |
| North Korea | NEPTUNE |
| Russia | RELIC |
| Cybercriminal | COMET |
This mirrors the logic behind established two-word taxonomies elsewhere in the industry, such as CrowdStrike’s “animal” system, where the second term also encodes origin or motivation while the first stays actor-specific.
Microsoft made a similar move recently, shifting to a weather-themed taxonomy that likewise pairs a descriptive category word with a unique actor name.
Google has been explicit that this is a phased rollout rather than a rip-and-replace overhaul. The company has initially renamed several dozen of its most actively tracked groups, with additional migrations continuing on a rolling basis.
Crucially, legacy names remain fully indexed and searchable inside the Google Threat Intelligence (GTI) platform, alongside preserved MITRE ATT&CK mappings and third-party vendor aliases, so analysts referencing older reporting or cross-checking against frameworks like ATT&CK won’t lose continuity.

Google has been candid about the limits of standardization: because no two vendors have identical visibility into the threat landscape, a “direct, apples-to-apples” mapping between different naming schemas is rarely achievable, even with a simplified system.
That caveat matters for practitioners who correlate Google’s cryptonyms against Microsoft’s weather names, CrowdStrike’s animal names, or Mandiant’s legacy UNC/APT designators when building unified threat pictures.
For threat intelligence analysts and content creators tracking adversary campaigns, the practical impact is twofold. Reports referencing groups like a China-nexus actor newly tagged with a “CASTLE” suffix, or a cybercriminal group under “COMET,” will need updated glossaries cross-referencing old and new names during the transition period.
Meanwhile, GTI’s preservation of legacy identifiers and ATT&CK mappings should limit disruption to existing detection rules, IOC feeds, and historical reporting that rely on names like APT41 or FIN clusters.
The shift reflects a broader industry recognition that as adversary tracking has proliferated across dozens of vendors, cognitive load, not lack of data, has become the bottleneck for defenders trying to act on intelligence quickly.