← Back to Feed

Updated Cyber Threat Actor Naming System

July 24, 2026 · Google Cloud Security · Severity: CRITICAL

Google Threat Intelligence Group is rolling out a unified naming schema for threat actors, using cryptonyms with two-word combinations. The first word is unique and memorable, while the second categorizes by motivation or origin, aiming to improve intuition and standardization.

Key Takeaways

  • Google Threat Intelligence Group introduces a unified cryptonym-based naming schema for threat actors.
  • The new system uses two-word combinations: a unique term and a category word for motivation or origin.
  • This replaces disparate identifiers like APT1 to provide intuitive context for defenders.
☕ Buy a Coffee