Google drops APT numbers for country-coded hacker codenames — SkimNews

Get the Tech newsletter
Daily tech — startups, AI labs, chips, the launches that shape the next decade. Free.
- Google revamped its hacking group naming system last month, replacing numeric APT designations (APT1, APT41) with memorable first names paired with a country-coded second word — Castle for China, Ion for Iran, Neptune for North Korea, and Relic for Russia.
- Mandiant, now part of Google, originally pioneered the APT numbering scheme; the revamp unifies Mandiant's naming conventions with Google's old Threat Analysis Group, which Shane Huntley previously headed.
- Google Threat Intelligence Group now tracks more than 5,000 "activity clusters" across several countries, according to chief analyst John Hultquist — a scale that made the old numeric scheme unwieldy.
- Huntley, now CTO of Google Threat Intelligence Group, said naming hackers lets defenders recognize patterns quickly: knowing how an actor behaves and what they've done before is "critically important" for incident response.
- State-sponsored hackers like North Korea's Lazarus Group are easier to track than cybercriminal groups or hackers-for-hire, because government hackers tend to have more consistent targets and activities.
- The cybersecurity industry remains fragmented — every company names groups differently based on its own telemetry — and Huntley acknowledged "no one has perfect visibility" even with shared data.
Why it matters: Google tracks 5,000-plus activity clusters while every major cybersecurity firm maintains its own naming scheme, making cross-vendor threat intelligence slower and more error-prone. Unifying Google's two internal taxonomies cuts one layer of confusion, but the broader problem — vendor refusal to converge on a single naming standard — stays unsolved.
Ask SkimNews

