Google Threat Intelligence Group's new two word schema for tracking hacking groups creates a parallel naming map, just as the rest of the industry was converging on a shared one.
Google Threat Intelligence Group published a new two-word naming schema for tracking hacking groups, just over a year after Microsoft, CrowdStrike, and a handful of other vendors launched a parallel effort to map the industry's labels onto each other. The Google scheme, unveiled on the Google Cloud threat intelligence blog, ships with its own fixed vocabulary for classifying attackers by motivation and origin, and asks the rest of the field to keep a second naming map rather than converge on one.
The Register reported on Monday that Google's rollout "suggests the relationship either wasn't consummated or didn't last," a reference to the June 2025 Microsoft-CrowdStrike strategic collaboration that named Google, Mandiant, and Palo Alto Networks' Unit 42 as future contributors. With Google now publishing its own public taxonomy (a fixed system for sorting attackers into named buckets), defenders who already maintain crosswalks between vendor labels will have to track a parallel map rather than a single shared one.
Every actor name under the new system is a two-word compound: a unique, memorable handle (preserving prior public monikers where possible, randomly generated otherwise to strip attribution bias), plus a fixed category word that pins the group to a motivation, origin, or activity type. The category vocabulary GTIG published maps CASTLE to People's Republic of China–aligned actors, ION to Iran, NEPTUNE to North Korea, RELIC to Russia, and COMET to cybercriminal activity that is not state-attributed. That second word is the part the rest of the field will have to either adopt, ignore, or translate, and it is the part that turns the Google schema into a structural fork rather than a cosmetic one.
GTIG pushed back on the fragmentation read in the same post. The group wrote that "no two organizations have the exact same visibility into the threat landscape, direct, apples-to-apples comparisons between threat actors are rarely possible," and called the new schema "a practical step toward managing a highly intricate tracking problem." The argument: Google sees enough of the world's network telemetry through its products, ad network, and Mandiant incident-response engagements that an internally consistent label set serves its defenders first, and asks the rest of the field to keep up.
GTIG said it "initially prioritized renaming several dozen of the most active groups" on a rolling basis; the full GTIG catalog is not being replaced overnight. Previous names remain indexed and searchable inside Google Threat Intelligence, with MITRE ATT&CK technique mappings and vendor aliases preserved alongside the new labels. Mandiant's older UNC ("uncategorized") designations will continue for clusters still in early investigation that do not yet have a stable public identity. The first batch is a precedent, not a complete migration.
Naming fights have geopolitical texture too. Beijing-aligned CVERC, China's cybersecurity response coordination body, has previously objected to popular Western monikers like "Typhoon," "Panda," and "Dragon," preferring neutral weather terms such as "Hurricane" and "Koala," according to The Register. That history is illustrative of why naming is contested terrain, not a Google rationale for the new schema. GTIG's own June 2025 commentary around the Microsoft-CrowdStrike effort had cast the alignment push as promising but incomplete; the weekend post is the company's first concrete taxonomy output since that exchange.
Defenders inside Google's own products get a label set that maps cleanly to the data Google actually sees. Everyone else inherits a second, parallel naming map to maintain alongside the shared one the rest of the industry is still building.