On July 24, 2026, Google Threat Intelligence Group (GTIG) rolled out a two word cryptonym system for naming cyber threat actors, replacing legacy Mandiant (UNC/APT) and TAG designations with memorable names like SANDW... The second word indicates attribution: CASTLE (China linked), ION (Iran linked), NEPTUNE (North...

Create a landscape editorial hero image for this Studio Global article: Search & fact-check with cited sources for What is Google's new unified two-word cryptonym system for naming cyber threat actors, announced. Article summary: All of the details in the question are confirmed by Google's own official announcement. Here is the verified summary.. Topic tags: general, general web, user generated. Style: premium digital editorial illustration, source-backed research mood, clean composition, high detail, modern web publication hero. Use reference image context only for broad subject, composition, and topical grounding; do not copy the exact image. Avoid: logos, brand marks, copyrighted characters, real person likenesses, fake screenshots, UI text, readable text, watermarks, charts with fake numbers, clickbait thumbnails, icons, and tiny thumbnail layouts. Make it useful as an illustrative v
Cybersecurity threat actors have long been tracked by alphanumeric codes like APT44 or UNC6508 — labels that communicate little about who the group is or what motivates them. On July 24, 2026, the Google Threat Intelligence Group (GTIG) announced a unified naming system that replaces those legacy identifiers with intuitive, two-word cryptonyms .
The new schema assigns each threat actor a pair of words :
| Second word | Meaning |
|---|---|
| CASTLE | People's Republic of China-linked |
| ION | Iran-linked |
| NEPTUNE | North Korea-linked |
| RELIC | Russia-linked |
| COMET | Cybercriminal |
The most prominent example is the reclassification of the former APT44 / Sandworm as SANDWORM RELIC . GTIG initially prioritized renaming several dozen of the most active groups, with the rest to follow on a rolling basis
.
Crucially, backward compatibility is preserved. Previous names remain indexed and searchable in the Google Threat Intelligence platform, and MITRE ATT&CK mappings plus other vendor aliases are maintained . For clusters still in early investigation, GTIG continues to use UNC ("uncategorized") designations
.
Google's move aligns with an industry-wide shift away from opaque sequential codes and toward more descriptive taxonomies. Microsoft uses a weather-themed system, CrowdStrike an animal-themed naming, and Palo Alto Networks a constellation-based approach . Notably, Google proceeded independently rather than joining the cross-vendor naming initiative Microsoft had been leading
.
The new system addresses a long-standing pain point for defenders: correlating threat actor names across products, reports, and platforms while trying to respond quickly to incidents.
Studio Global AI
Use this topic as a starting point for a fresh source-backed answer, then compare citations before you share it.
On July 24, 2026, Google Threat Intelligence Group (GTIG) rolled out a two word cryptonym system for naming cyber threat actors, replacing legacy Mandiant (UNC/APT) and TAG designations with memorable names like SANDW...
On July 24, 2026, Google Threat Intelligence Group (GTIG) rolled out a two word cryptonym system for naming cyber threat actors, replacing legacy Mandiant (UNC/APT) and TAG designations with memorable names like SANDW... The second word indicates attribution: CASTLE (China linked), ION (Iran linked), NEPTUNE (North Korea linked), RELIC (Russia linked), or COMET (cybercriminal).