← Back to Feed
Updated Cyber Threat Actor Naming System
July 24, 2026 · Google Cloud Security · Severity: CRITICAL
Google Threat Intelligence Group is rolling out a unified naming schema for threat actors, using cryptonyms with two-word combinations. The first word is unique and memorable, while the second categorizes by motivation or origin, aiming to improve intuition and standardization.
Key Takeaways
- Google Threat Intelligence Group introduces a unified cryptonym-based naming schema for threat actors.
- The new system uses two-word combinations: a unique term and a category word for motivation or origin.
- This replaces disparate identifiers like APT1 to provide intuitive context for defenders.