Threat reportThreat IntelligenceTL-2026-2608
Google Threat Intelligence Group Unifies Threat Actor Naming Under New Cryptonym System
Google Threat Intelligence Group Unifies Threat Actor Naming (TL-2026-2608) is a low-severity tracked intrusion set, first published 2026-07-24. It has no confirmed attribution, affects Google Google Threat Intelligence (GTI) platform / GTIG threat-actor, maps to 16 MITRE ATT&CK techniques (T1003, T1021, T1027), and is covered by 9 detection rules and 25 indicators of compromise.
- Severity
- LOWAssessed severity
- CVEs
- 0None referenced
- Techniques
- 16MITRE ATT&CK
- Actors
- 0Not attributed
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 25Indicators of compromise
Key facts for TL-2026-2608
- Threat ID
- TL-2026-2608
- Severity
- LOW
- Status
- ACTIVE
- Category
- THREAT_INTEL
- First published
- Last reviewed
- Attribution confidence
- LOW
- Motivation
- UNKNOWN
- Detection rules
- 9
- Indicators of compromise
- 25
Malware and tooling in Google Threat Intelligence Group Unifies Threat Actor Naming
Malware and tooling: Turla
How Google Threat Intelligence Group Unifies Threat Actor Naming works
Google Threat Intelligence Group (GTIG) has replaced the separate Mandiant and Threat Analysis Group (TAG) tracking schemas with a single two-word cryptonym system (e.g. LAKE RELIC for APT28, SPIRE CASTLE for APT41, WILD COMET for FIN7), renaming several dozen of its most-tracked threat actors while preserving legacy names, MITRE ATT&CK mappings, and vendor aliases for cross-reference. The rollout has drawn industry criticism for adding yet another naming scheme to an already fragmented threat-actor-naming landscape.
On July 24, 2026, Google Threat Intelligence Group (GTIG) published a blog post announcing a unified, cryptonym-based naming convention for the threat actors it tracks, replacing the two parallel systems that Mandiant and Google's Threat Analysis Group (TAG) had maintained independently before their merger into GTIG. Each tracked actor now receives a two-word cryptonym: a first word that is unique to the specific cluster (preferably reused from existing public reporting, or randomly generated and analyst-vetted if no prior term exists) and a second word that encodes the assessed origin, motivation, or activity type most relevant to defenders -- CASTLE for actors attributed to the People's Republic of China, ION for Iran, NEPTUNE for North Korea, RELIC for Russia, and COMET for financially motivated cybercriminal groups.
GTIG renamed several dozen of its most active clusters in the initial rollout, prioritizing the groups most relevant to current defensive operations, with additional actors to be renamed on a rolling basis going forward; unattributed or early-stage clusters continue to use GTIG's existing 'UNC' designation. Prominent renames include APT28/FROZENLAKE to LAKE RELIC, APT29/ICECAP to ICE RELIC, APT44/FROZENBARENTS (Sandworm) to SANDWORM RELIC, APT41 to SPIRE CASTLE, APT31 to TIDE CASTLE, APT40 to ISLAND CASTLE, FIN7 to WILD COMET, FIN11 to RAZOR COMET, APT34 (OilRig) to SOLAR ION, APT42/CALANQUE to CALANQUE ION, APT37 to PLAIN NEPTUNE, and APT45 to GRASS NEPTUNE, among many others. On July 30, 2026, GTIG updated the original post to add a full reference table of renamed clusters.
GTIG states the goal is to streamline internal operations and facilitate mapping to other vendors' taxonomies, arguing that two-word combinations are more intuitive and memorable for defenders than sequential APT/FIN numbers. Previous identifiers remain indexed and searchable inside the Google Threat Intelligence (GTI) platform, and GTIG explicitly preserves each cluster's existing MITRE ATT&CK group mapping and other vendors' aliases for cross-reference -- this is a taxonomy/rebranding change, not a new attack, campaign, or technical disclosure, and GTIG itself cautions that because no two organizations share identical visibility into the threat landscape, direct actor-to-actor comparisons across vendor taxonomies remain rarely possible even with aligned second-word categories.
The announcement drew immediate industry commentary. Coverage from SecurityWeek and Help Net Security reported GTIG's own framing that the system is 'intentionally... as simple as possible... to streamline operations and facilitate mapping to other naming taxonomies.' Critical commentary, notably from Mathew J. Schwartz at BankInfoSecurity (July 27, 2026) and CSO Online (July 31, 2026), argued the new schema adds to an already fragmented landscape -- BankInfoSecurity noted that APT44/Sandworm alone already carried at least 13 prior synonyms (including FROZENBARENTS and HADES) before GTIG added a 14th, and cited security researcher Daniel Cuthbert's criticism that the industry 'cannot continue with so many names for the same criminals.' CSO Online argued Google could instead have standardized on one of its own two legacy systems, or adopted an existing external taxonomy (e.g. Microsoft's weather-themed system introduced in 2023), rather than introducing a third. Because this rename directly changes how dozens of well-documented, high-activity threat actors are labeled going forward, it is relevant to any downstream threat intelligence that references these groups by legacy APT/FIN/UNC designations, and to actor-attribution grounding and alias-mapping logic across threat intelligence platforms.
MITRE ATT&CK techniques used in TL-2026-2608
Credential Access
Lateral Movement
Defense Evasion
T1027 Obfuscated Files or Information; T1036 Masquerading
Persistence
T1053 Scheduled Task/Job; T1078 Valid Accounts; T1547 Boot or Logon Autostart Execution
Execution
T1059 Command and Scripting Interpreter; T1059.007 Command and Scripting Interpreter: JavaScript
Command and Control
T1071 Application Layer Protocol
Discovery
T1082 System Information Discovery
Initial Access
T1190 Exploit Public-Facing Application; T1195 Supply Chain Compromise; T1566 Phishing
Impact
Resource Development
Affected products and versions in Google Threat Intelligence Group Unifies Threat Actor Naming
- Google — Google Threat Intelligence (GTI) platform / GTIG threat-actor taxonomy
Remediation for Google Threat Intelligence Group Unifies Threat Actor Naming
Immediate actions
- Update threat intelligence platforms, SIEM watchlists, and detection-rule metadata to map legacy APT/FIN/UNC designations to their new GTIG cryptonyms (e.g. APT28 -> LAKE RELIC, FIN7 -> WILD COMET) so existing alerting and reporting is not orphaned by the rename
- Audit internal runbooks, playbooks, and threat-actor dossiers for hardcoded legacy names and add the new cryptonyms as cross-reference aliases rather than replacing the legacy names outright
Workarounds
- Continue referencing legacy APT/FIN numbers in parallel with new cryptonyms during the transition period, since GTIG's rollout is partial (only several dozen of the most active clusters renamed so far) and unrenamed clusters retain their prior designations or UNC numbers
Longer-term hardening
- Maintain an actor-alias crosswalk table spanning GTIG cryptonyms, MITRE ATT&CK group IDs, and other vendor taxonomies (Microsoft, CrowdStrike, Mandiant legacy, Trend Micro) to prevent attribution fragmentation across intelligence sources
- Prefer MITRE ATT&CK group IDs (e.g. G0007, G0096) as the durable cross-vendor join key for actor attribution, since GTIG explicitly preserves ATT&CK mappings across the rename while vendor-specific names continue to proliferate
Timeline of Google Threat Intelligence Group Unifies Threat Actor Naming
- Google Threat Intelligence Group (GTIG) publishes its blog post announcing the unified cryptonym-based threat-actor naming system, replacing the separate Mandiant and TAG tracking schemas.
- BankInfoSecurity's Mathew J. Schwartz publishes 'Insane Castle Hurricane: APT Codename Confusion Proliferates,' arguing the new naming adds to an already fragmented landscape and citing that APT44/Sandworm already had at least 13 prior synonyms; quotes researcher Daniel Cuthbert criticizing the proliferation of actor names.
- Help Net Security publishes coverage of the GTIG rename, summarizing the CASTLE/ION/NEPTUNE/RELIC/COMET category system and citing GTIG's rationale for the change.
- SecurityWeek reports on the rollout, quoting GTIG's statement that the system is intended to be 'as simple as possible... to streamline operations and facilitate mapping to other naming taxonomies.'
- GTIG updates the original blog post to add a full reference table listing every renamed threat-actor cluster and its new cryptonym.
- CSO Online publishes 'Google creates another set of names for threat actors,' arguing Google could have standardized on an existing internal or external taxonomy instead of introducing a third naming system.
Sources cited for Google Threat Intelligence Group Unifies Threat Actor Naming
- Updated Cyber Threat Actor Naming System
- Google changes how it names cyber threat actors
- Insane Castle Hurricane: APT Codename Confusion Proliferates
- Google Adopts New Threat Actor Naming System
- Google creates another set of names for threat actors
- MITRE ATT&CK Group Profile: APT28
- MITRE ATT&CK Group Profile: APT41
- MITRE ATT&CK Group Profile: FIN7
- MITRE ATT&CK Group Profile: Sandworm Team
Detection coverage for TL-2026-2608
As of 2026-07-24, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2608 across Splunk SPL, Microsoft KQL and Sigma, covering 25 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.