Threat reportThreat IntelligenceTL-2026-2608

Google Threat Intelligence Group Unifies Threat Actor Naming Under New Cryptonym System

lowACTIVE

Google Threat Intelligence Group Unifies Threat Actor Naming (TL-2026-2608) is a low-severity tracked intrusion set, first published 2026-07-24. It has no confirmed attribution, affects Google Google Threat Intelligence (GTI) platform / GTIG threat-actor, maps to 16 MITRE ATT&CK techniques (T1003, T1021, T1027), and is covered by 9 detection rules and 25 indicators of compromise.

Severity
LOWAssessed severity
CVEs
0None referenced
Techniques
16MITRE ATT&CK
Actors
0Not attributed
Detection rules
9SPL · KQL · Sigma
IOCs
25Indicators of compromise

Key facts for TL-2026-2608

Threat ID
TL-2026-2608
Severity
LOW
Status
ACTIVE
Category
THREAT_INTEL
First published
Last reviewed
Attribution confidence
LOW
Motivation
UNKNOWN
Detection rules
9
Indicators of compromise
25

Malware and tooling in Google Threat Intelligence Group Unifies Threat Actor Naming

Malware and tooling: Turla

How Google Threat Intelligence Group Unifies Threat Actor Naming works

Google Threat Intelligence Group (GTIG) has replaced the separate Mandiant and Threat Analysis Group (TAG) tracking schemas with a single two-word cryptonym system (e.g. LAKE RELIC for APT28, SPIRE CASTLE for APT41, WILD COMET for FIN7), renaming several dozen of its most-tracked threat actors while preserving legacy names, MITRE ATT&CK mappings, and vendor aliases for cross-reference. The rollout has drawn industry criticism for adding yet another naming scheme to an already fragmented threat-actor-naming landscape.

On July 24, 2026, Google Threat Intelligence Group (GTIG) published a blog post announcing a unified, cryptonym-based naming convention for the threat actors it tracks, replacing the two parallel systems that Mandiant and Google's Threat Analysis Group (TAG) had maintained independently before their merger into GTIG. Each tracked actor now receives a two-word cryptonym: a first word that is unique to the specific cluster (preferably reused from existing public reporting, or randomly generated and analyst-vetted if no prior term exists) and a second word that encodes the assessed origin, motivation, or activity type most relevant to defenders -- CASTLE for actors attributed to the People's Republic of China, ION for Iran, NEPTUNE for North Korea, RELIC for Russia, and COMET for financially motivated cybercriminal groups.

GTIG renamed several dozen of its most active clusters in the initial rollout, prioritizing the groups most relevant to current defensive operations, with additional actors to be renamed on a rolling basis going forward; unattributed or early-stage clusters continue to use GTIG's existing 'UNC' designation. Prominent renames include APT28/FROZENLAKE to LAKE RELIC, APT29/ICECAP to ICE RELIC, APT44/FROZENBARENTS (Sandworm) to SANDWORM RELIC, APT41 to SPIRE CASTLE, APT31 to TIDE CASTLE, APT40 to ISLAND CASTLE, FIN7 to WILD COMET, FIN11 to RAZOR COMET, APT34 (OilRig) to SOLAR ION, APT42/CALANQUE to CALANQUE ION, APT37 to PLAIN NEPTUNE, and APT45 to GRASS NEPTUNE, among many others. On July 30, 2026, GTIG updated the original post to add a full reference table of renamed clusters.

GTIG states the goal is to streamline internal operations and facilitate mapping to other vendors' taxonomies, arguing that two-word combinations are more intuitive and memorable for defenders than sequential APT/FIN numbers. Previous identifiers remain indexed and searchable inside the Google Threat Intelligence (GTI) platform, and GTIG explicitly preserves each cluster's existing MITRE ATT&CK group mapping and other vendors' aliases for cross-reference -- this is a taxonomy/rebranding change, not a new attack, campaign, or technical disclosure, and GTIG itself cautions that because no two organizations share identical visibility into the threat landscape, direct actor-to-actor comparisons across vendor taxonomies remain rarely possible even with aligned second-word categories.

The announcement drew immediate industry commentary. Coverage from SecurityWeek and Help Net Security reported GTIG's own framing that the system is 'intentionally... as simple as possible... to streamline operations and facilitate mapping to other naming taxonomies.' Critical commentary, notably from Mathew J. Schwartz at BankInfoSecurity (July 27, 2026) and CSO Online (July 31, 2026), argued the new schema adds to an already fragmented landscape -- BankInfoSecurity noted that APT44/Sandworm alone already carried at least 13 prior synonyms (including FROZENBARENTS and HADES) before GTIG added a 14th, and cited security researcher Daniel Cuthbert's criticism that the industry 'cannot continue with so many names for the same criminals.' CSO Online argued Google could instead have standardized on one of its own two legacy systems, or adopted an existing external taxonomy (e.g. Microsoft's weather-themed system introduced in 2023), rather than introducing a third. Because this rename directly changes how dozens of well-documented, high-activity threat actors are labeled going forward, it is relevant to any downstream threat intelligence that references these groups by legacy APT/FIN/UNC designations, and to actor-attribution grounding and alias-mapping logic across threat intelligence platforms.

MITRE ATT&CK techniques used in TL-2026-2608

Credential Access

T1003 OS Credential Dumping

Lateral Movement

T1021 Remote Services

Defense Evasion

T1027 Obfuscated Files or Information; T1036 Masquerading

Persistence

T1053 Scheduled Task/Job; T1078 Valid Accounts; T1547 Boot or Logon Autostart Execution

Execution

T1059 Command and Scripting Interpreter; T1059.007 Command and Scripting Interpreter: JavaScript

Command and Control

T1071 Application Layer Protocol

Discovery

T1082 System Information Discovery

Initial Access

T1190 Exploit Public-Facing Application; T1195 Supply Chain Compromise; T1566 Phishing

Impact

T1485 Data Destruction

Resource Development

T1584 Compromise Infrastructure

Affected products and versions in Google Threat Intelligence Group Unifies Threat Actor Naming

  • Google — Google Threat Intelligence (GTI) platform / GTIG threat-actor taxonomy

Remediation for Google Threat Intelligence Group Unifies Threat Actor Naming

Immediate actions

  • Update threat intelligence platforms, SIEM watchlists, and detection-rule metadata to map legacy APT/FIN/UNC designations to their new GTIG cryptonyms (e.g. APT28 -> LAKE RELIC, FIN7 -> WILD COMET) so existing alerting and reporting is not orphaned by the rename
  • Audit internal runbooks, playbooks, and threat-actor dossiers for hardcoded legacy names and add the new cryptonyms as cross-reference aliases rather than replacing the legacy names outright

Workarounds

  • Continue referencing legacy APT/FIN numbers in parallel with new cryptonyms during the transition period, since GTIG's rollout is partial (only several dozen of the most active clusters renamed so far) and unrenamed clusters retain their prior designations or UNC numbers

Longer-term hardening

  • Maintain an actor-alias crosswalk table spanning GTIG cryptonyms, MITRE ATT&CK group IDs, and other vendor taxonomies (Microsoft, CrowdStrike, Mandiant legacy, Trend Micro) to prevent attribution fragmentation across intelligence sources
  • Prefer MITRE ATT&CK group IDs (e.g. G0007, G0096) as the durable cross-vendor join key for actor attribution, since GTIG explicitly preserves ATT&CK mappings across the rename while vendor-specific names continue to proliferate

Timeline of Google Threat Intelligence Group Unifies Threat Actor Naming

  • Google Threat Intelligence Group (GTIG) publishes its blog post announcing the unified cryptonym-based threat-actor naming system, replacing the separate Mandiant and TAG tracking schemas.
  • BankInfoSecurity's Mathew J. Schwartz publishes 'Insane Castle Hurricane: APT Codename Confusion Proliferates,' arguing the new naming adds to an already fragmented landscape and citing that APT44/Sandworm already had at least 13 prior synonyms; quotes researcher Daniel Cuthbert criticizing the proliferation of actor names.
  • Help Net Security publishes coverage of the GTIG rename, summarizing the CASTLE/ION/NEPTUNE/RELIC/COMET category system and citing GTIG's rationale for the change.
  • SecurityWeek reports on the rollout, quoting GTIG's statement that the system is intended to be 'as simple as possible... to streamline operations and facilitate mapping to other naming taxonomies.'
  • GTIG updates the original blog post to add a full reference table listing every renamed threat-actor cluster and its new cryptonym.
  • CSO Online publishes 'Google creates another set of names for threat actors,' arguing Google could have standardized on an existing internal or external taxonomy instead of introducing a third naming system.

Sources cited for Google Threat Intelligence Group Unifies Threat Actor Naming

Detection coverage for TL-2026-2608

As of 2026-07-24, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2608 across Splunk SPL, Microsoft KQL and Sigma, covering 25 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
25 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats