In July–August 2026, Google Threat Intelligence Group retired the Mandiant era APT numbering system (APT1, APT41, etc.) and introduced a two word cryptonym: a memorable random first name paired with a second word indi... The overhaul addresses a critical industry problem: every major security vendor uses a different...
Research answer

Create a landscape editorial hero image for this Studio Global article: Why do cybersecurity companies assign code names to hacking groups, what challenges arise from different companies using different naming sy. Article summary: Here is a concise breakdown of what the evidence shows across all four parts of your question.. Topic tags: general, general web, news. Style: premium digital editorial illustration, source-backed research mood, clean composition, high detail, modern web publication hero. Use reference image context only for broad subject, composition, and topical grounding; do not copy the exact image. Avoid: logos, brand marks, copyrighted characters, real person likenesses, fake screenshots, UI text, readable text, watermarks, charts with fake numbers, clickbait thumbnails, icons, and tiny thumbnail layouts. Make it useful as an illustrative visual, not as factual evidence.
In the world of cybersecurity, knowing who is attacking matters as much as how they attacked. But for years, the industry has struggled with a fundamental coordination problem: every major vendor calls the same hacking group by a different name. A Russian cyberspy group is APT28 to Mandiant, Fancy Bear to CrowdStrike, and Strontium to Microsoft—and that fragmentation can cost precious hours during an active breach .
In July–August 2026, Google Threat Intelligence Group (GTIG) took aim at this chaos by retiring its legacy APT numbering system and introducing a new two-word cryptonym format designed for clarity at a glance .
Code names exist because cybersecurity researchers need a shared, persistent label for a cluster of malicious activity long before anyone can prove individual legal identities or make a formal law enforcement attribution . As Google's Shane Huntley, CTO of GTIG, explained in interviews, a codename acts as a "persistent anchor"—allowing analysts across different organizations, continents, and industries to instantly share intelligence about the same adversary
. A properly named group turns a diffuse collection of IPs, malware signatures, and observed tactics into a trackable entity that can be studied over years
.
Before a hacking group receives a permanent name, it typically starts as a temporary tracking cluster, designated with a UNC (Uncategorized) label and a numeric identifier, such as UNC1878 . Only after enough evidence accumulates does the group graduate to a named codename.
The growth of the threat landscape has overwhelmed the old approach. Google's Chief Analyst John Hultquist noted that the company now tracks over 5,000 "activity clusters" across multiple countries—a volume that makes any single numeric taxonomy unworkable . With that many entities, sequential APT numbers became as confusing as they were helpful.
"Oftentimes, even industry insiders can't keep track," Huntley told TechCrunch . Each security vendor has its own taxonomy. Microsoft uses weather-themed names (Nobelium, Seashell Blizzard), CrowdStrike uses animal-themed names (Cozy Bear, Fancy Bear), and Palo Alto Networks uses its own system (e.g., Muddled Libra)
. This fragmentation slows incident response because teams waste time reconciling labels instead of containing the damage
. Huntley explained that getting different companies to adopt one universal system isn't realistic, because each organization has different visibility, different data, and different operational needs
.
GTIG's new naming system replaces Mandiant's legacy APT numeric sequence (APT1, APT41, etc.) and unifies the naming approaches that had developed independently inside Google's Threat Analysis Group and Mandiant .
The new format has two parts :
The system is not limited to these four categories; Google has built the taxonomy to accommodate additional category words as needed . Huntley said the change was designed to make it "easier for researchers inside and outside the company to clearly identify different threat groups" and to let defenders understand an attacker's origin, motives, and activity type at a glance
.
While the naming overhaul helps, it does not solve the most fundamental difficulty in threat intelligence: clearly separating state-sponsored advanced persistent threats from cybercriminal gangs and commercial hacker-for-hire operations .
These categories overlap significantly in practice. State-aligned groups sometimes adopt criminal ransomware tactics to generate revenue or disguise their origins . Criminal groups sell access and tooling to government-backed actors. Hacker-for-hire firms operate across both worlds. The personnel, tools, and effects are often indistinguishable
.
Hultquist has pointed out that Google's 5,000+ tracked clusters include state actors, cybercriminals, and mercenary spyware vendors—and the boundaries blur constantly . AI-generated phishing and automated reconnaissance tools further muddy the lines, making it harder to distinguish between a state-sponsored intelligence operation and a financially motivated crime ring
.
Google's new naming system helps by embedding country-of-origin context directly into each group's label, but it cannot resolve the underlying ambiguity: a group might operate as a state-backed espionage unit in one campaign and as a freelance ransomware operator in another, and groups frequently rebrand or share infrastructure .
Code names provide critical shared vocabulary for tracking adversaries across the cybersecurity industry. But inconsistent vendor naming systems created dangerous confusion. Google's new two-word scheme—a random first name paired with a country-indicating second word—directly tackles that fragmentation for its own tracking of 5,000+ clusters. The change makes it easier for defenders to quickly understand who they are facing. Yet the deeper difficulty of separating state actors from criminals and mercenaries remains an ongoing operational challenge that no naming reform can fully solve.
Studio Global AI
This page includes a source-backed answer you can continue inside Studio Global.
In July–August 2026, Google Threat Intelligence Group retired the Mandiant era APT numbering system (APT1, APT41, etc.) and introduced a two word cryptonym: a memorable random first name paired with a second word indi...
In July–August 2026, Google Threat Intelligence Group retired the Mandiant era APT numbering system (APT1, APT41, etc.) and introduced a two word cryptonym: a memorable random first name paired with a second word indi... The overhaul addresses a critical industry problem: every major security vendor uses a different naming system for the same hacking groups, causing confusion that slows incident response and threat intelligence sharin...
Tracking state backed, cybercriminal, and hacker for hire groups separately remains a fundamental challenge—their tools, infrastructure, and personnel frequently overlap—but Google's codenames embed country of origin...