Google GTIG Adopts Two-Word Threat Actor Naming Taxonomy — Sandworm/APT44 Redesignated SANDWORM RELIC — Threadlinqs Intelligence
As of 2026-07-27, Google GTIG Adopts Two-Word Threat Actor Naming Taxonomy — Sandworm/APT44 Redesignated SANDWORM RELIC is a info-severity threat intel threat attributed to Sandworm (Russia), tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 27 indicators of compromise.
Threat ID: TL-2026-1730 · Severity: INFO · Status: ACTIVE · Category: THREAT_INTEL
Attribution: Sandworm · Russia · DESTRUCTION
Google Threat Intelligence Group (GTIG) has replaced its parallel Mandiant/TAG naming systems with a unified two-word cryptonym taxonomy — first word as unique identifier, second word encoding
Google Threat Intelligence Group (GTIG) announced on July 24, 2026 a unified, two-word cryptonym naming taxonomy for tracking cyber threat actors, replacing the parallel — and increasingly redundant — naming systems inherited separately from Mandiant (acquired 2022) and Google's in-house Threat Analysis Group (TAG). The first word of each cryptonym is a memorable, unique identifier (preferably carried over from prior public reporting, or randomly generated and bias-reviewed for newly discovered clusters); the second word encodes attribution or motivation: CASTLE for People's Republic of China-linked groups, ION for Iran-linked groups, NEPTUNE for North Korea-linked groups, RELIC for Russia-linked groups, and COMET for financially motivated cybercriminal groups. Groups whose attribution remains unresolved continue to be tracked under the legacy 'UNC' (uncategorized) designation. Google framed the change around the principle that 'threat tracking shouldn't be an exercise in memorization, but rather one of intuition,' and positioned it alongside — but distinct from — CrowdStrike's animal-based taxonomy (PANDA/BEAR/SPIDER/JACKAL) and Microsoft's April 2023 weather-based taxonomy (Typhoon/Blizzard/Sandstorm/Tempest), and a 2025 Microsoft-CrowdStrike alias-mapping initiative that translates between systems rather than standardizing on one.
GTIG has renamed several dozen of its most actively tracked groups in the initial rollout, with additional renamings continuing on a rolling basis; all legacy names remain indexed and searchable in the Google Threat Intelligence (GTI) platform alongside MITRE ATT&CK mappings and third-party vendor aliases, so existing detections, dossiers, and CTI feeds keyed to old names are not orphaned. The only renaming confirmed by name in initial reporting is Sandworm — long tracked by Mandiant as APT44 — which is now designated SANDWORM RELIC, reflecting its confirmed, high-confidence attribution to Russia's GRU (Main Intelligence Directorate) Main Center for Special Technologies (GTsST), military unit 74455.
This naming change is itself non-technical (no new exploit, campaign, or vulnerability is being reported), but it has direct operational relevance for defenders: any detection content, threat feed, dossier, or SOC runbook that references 'APT44,' 'Sandworm,' 'Voodoo Bear,' 'Telebots,' 'IRON VIKING,' 'ELECTRUM,' 'Quedagh,' 'Seashell Blizzard,' or 'FROZENBARENTS' now has an equivalent GTIG label of SANDWORM RELIC, and alias-mapping tables should be updated accordingly to avoid detection or correlation gaps. Sandworm/APT44/SANDWORM RELIC is one of the most consequential and longest-running Russian state threat actors in the public record: active since at least 2009, it is responsible for the 2014 'Sandworm Team' PowerPoint/OLE zero-day campaign (CVE-2014-4114) against NATO and Ukrainian/European government and energy targets; the December 2015 and December 2016 Ukrainian power-grid attacks (BlackEnergy, Industroyer); the June 2017 NotPetya global wiper outbreak disguised as ransomware; the February 2018 Olympic Destroyer attack on Pyeongchang Winter Olympics IT systems; the 2018 VPNFilter SOHO-router botnet (500,000+ infected devices); the 2017-2020 Centreon-based intrusion campaign against French IT/hosting providers documented by ANSSI; the wave of destructive wipers (WhisperGate, HermeticWiper, IsaacWiper) deployed against Ukraine in the run-up to the February 2022 invasion; and the April 2022 Industroyer2/CaddyWiper attack attempted (and disrupted before causing an outage) against a Ukrainian energy provider. This research record documents the naming-taxonomy change and consolidates the sourced, publicly documented TTPs, malware, and indicators tied to the renamed entity for cross-referencing and alias-mapping in the Threadlinqs platform.
Target sectors: government administration, critical infrastructure, energy, information technology, telecoms, defense, logistics, hosting providers, academic
Target regions: ukraine, Europe, united states of america, NATO member states, 151 - Eastern Europe
References
- Google changes how it names cyber threat actors
- Updated Cyber Threat Actor Naming System
- Google's solution to hacker name confusion? Yet another naming system
- Google rolls out new naming system for cyber threat actors
- Google Is Giving Hacker Groups New Names That Reveal Who They Are and Why They Attack
- Google Launches Unified Cryptonym-Based Naming System for Threat Actors
- Insane Castle Hurricane: APT Codename Confusion Proliferates
- Google introduces standardized nomenclature for Cyber Threat Groups
- Sandworm Team, ELECTRUM, Telebots, IRON VIKING, BlackEnergy (Group), Quedagh, Voodoo Bear, IRIDIUM, Seashell Blizzard, FROZENBARENTS, APT44 (G0034)
- Unearthing APT44: Russia's Notorious Cyber Sabotage Unit Sandworm
- Update: Destructive Malware Targeting Organizations in Ukraine (AA22-057A)
- MAR-10376640-2.v1 – CaddyWiper
- New VPNFilter malware targets at least 500K networking devices worldwide
- Sandworm (Threat Actor)
- Sandworm Hackers Hit French Monitoring Software Vendor Centreon
Detections & IOCs
As of 2026-08-10, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 27 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
THREAT_INTEL, INFO, threat intelligence, cybersecurity, CVE-2014-4114, T1595, T1594, T1583, T1584, T1588, T1190, T1566, T1133, T1195, T1059