Google has overhauled the way it names hacking groups, replacing the APT numbering system with memorable first names and a second word indicating the country of origin. The new system uses Castle for China, Ion for Iran, Neptune for North Korea and Relic for Russia.
Shane Huntley, chief technology officer of Google Threat Intelligence Group, said the revamp was necessary to bring clarity to security researchers. He told TechCrunch that in the early 2010s, when companies began naming hackers, "we were not expecting to have as many threat groups as we do today."
Google now tracks more than 5,000 "activity clusters" in several countries, according to John Hultquist, chief analyst at Google Threat Intelligence Group. Huntley said very few developed nations lack their own cyber capabilities and hacking groups.
Huntley explained that naming groups gives defenders a baseline understanding of who is attacking whom and how, which helps organisations recognise threats more quickly and investigate incidents. He noted that tracking state-sponsored hackers is easier than tracking cybercriminal groups, which are more amorphous.
Asked why companies do not all use the same codenames, Huntley said every company has a different view of each group based on its own data. "No one has perfect visibility," he said. "We are building our model and our best understanding, but we will never know everything about what's going on."