Thursday, August 27, 2026
Tech Beat
Aug 8, 2026, 3:00 PMCybersecurity

Google Reworks Hacker Codenames to Track 5,000 Threat Clusters

Google unifies its Threat Analysis Group and Mandiant naming systems while tracking 5,000 plus activity clusters, helping defenders act on threats faster.

A prism sorts tangled masks into four streams, symbolizing Google’s clearer hacker naming system.
Listen to this briefingAudio briefing

Summary

In July 2026, Google replaced Mandiant’s numbered labels, including APT1 and APT41, with one system spanning Mandiant and Google’s old Threat Analysis Group, formerly headed by Shane Huntley, now chief technology officer of Google Threat Intelligence Group. Each hacking group receives a memorable random first name and a second word whose initial identifies its origin: Castle for China, Ion for Iran, Neptune for North Korea and Relic for Russia. Mandiant, now part of Google, pioneered industry naming more than a decade ago. The consolidation leaves researchers one fewer competing codebook.

Google tracks more than 5,000 activity clusters across several countries, chief analyst John Hultquist said, while Huntley said few developed nations lack cyber capabilities and hacking groups. Consistent labels establish who attacks whom and how, helping organizations recognize, prepare for, stop or investigate threats faster. Past behavior, goals and sponsorship, as with North Korea’s Lazarus Group, guide incident response and defensive coverage. State sponsored actors are easier to follow because their targets and operations are steadier. Cybercriminal memberships shift and splinter, while hackers for hire and spyware makers serve customers worldwide. A universal vocabulary remains unlikely because each company sees different data and telemetry, and information sharing cannot eliminate incomplete visibility.

Positives

  • Google’s July 2026 overhaul unifies Mandiant and the former Threat Analysis Group under one hacker naming system.
  • Castle, Ion, Neptune and Relic immediately indicate links to China, Iran, North Korea and Russia.
  • More than 5,000 activity clusters are tracked by Google Threat Intelligence Group across several countries.
  • Consistent actor histories help organizations recognize attacks, strengthen coverage and accelerate investigations and incident response.

Risks & concerns

  • More than 5,000 activity clusters have made threat actors difficult to track, even for cybersecurity industry insiders.
  • Few developed nations lack cyber capabilities and hacking groups, according to Shane Huntley.
  • Cybercriminal groups change members and splinter, making them less consistent than state sponsored actors.
  • Hackers for hire and spyware makers serve customers across multiple countries, complicating attribution.
  • Different corporate telemetry produces incompatible codenames and prevents a universal industry vocabulary, even when researchers share information.
Primary sourceTechCrunchhttps://techcrunch.com/2026/08/08/googles-top-hacker-hunter-explains-why-hacking-groups-get-codenames/
Read full article
Editorial note: Tech Beat summarizes and analyzes third-party reporting. The source link is the authoritative article. This page does not reproduce the full source text.

More From The Wire

CybersecurityAug 27

Visa VVAH AI Patches Code Before Human Review

CybersecurityAug 26

Boston Scientific Cyberattack Disrupts Global Shipments and Order Processing

CybersecurityAug 26

FBI Cripples China-Backed QTFY Botnet Used to Hack NASA and US Senate