# Google Threat Intelligence Group Unifies Threat Actor Naming Under New Cryptonym System

> Google Threat Intelligence Group (GTIG) has replaced the separate Mandiant and Threat Analysis Group (TAG) tracking schemas with a single two-word cryptonym system (e.g. LAKE RELIC for APT28, SPIRE CASTLE for APT41, WILD COMET for FIN7), renaming several dozen of its most-tracked threat actors while preserving legacy names, MITRE ATT&CK mappings, and vendor aliases for cross-reference. The rollout has drawn industry criticism for adding yet another naming scheme to an already fragmented threat-actor-naming landscape.

- **Published:** 2026-07-24T00:00:00Z
- **Last reviewed:** 2026-07-24T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-2608
- **ID:** TL-2026-2608
- **Severity:** LOW
- **Category:** THREAT_INTEL
- **Status:** ACTIVE
- **Detections:** 9 · **IOCs:** 25 (full data via the Threadlinqs MCP server — Purple tier)

## Description

On July 24, 2026, Google Threat Intelligence Group (GTIG) published a blog post announcing a unified, cryptonym-based naming convention for the threat actors it tracks, replacing the two parallel systems that Mandiant and Google's Threat Analysis Group (TAG) had maintained independently before their merger into GTIG. Each tracked actor now receives a two-word cryptonym: a first word that is unique to the specific cluster (preferably reused from existing public reporting, or randomly generated and analyst-vetted if no prior term exists) and a second word that encodes the assessed origin, motivation, or activity type most relevant to defenders -- CASTLE for actors attributed to the People's Republic of China, ION for Iran, NEPTUNE for North Korea, RELIC for Russia, and COMET for financially motivated cybercriminal groups.

GTIG renamed several dozen of its most active clusters in the initial rollout, prioritizing the groups most relevant to current defensive operations, with additional actors to be renamed on a rolling basis going forward; unattributed or early-stage clusters continue to use GTIG's existing 'UNC' designation. Prominent renames include APT28/FROZENLAKE to LAKE RELIC, APT29/ICECAP to ICE RELIC, APT44/FROZENBARENTS (Sandworm) to SANDWORM RELIC, APT41 to SPIRE CASTLE, APT31 to TIDE CASTLE, APT40 to ISLAND CASTLE, FIN7 to WILD COMET, FIN11 to RAZOR COMET, APT34 (OilRig) to SOLAR ION, APT42/CALANQUE to CALANQUE ION, APT37 to PLAIN NEPTUNE, and APT45 to GRASS NEPTUNE, among many others. On July 30, 2026, GTIG updated the original post to add a full reference table of renamed clusters.

GTIG states the goal is to streamline internal operations and facilitate mapping to other vendors' taxonomies, arguing that two-word combinations are more intuitive and memorable for defenders than sequential APT/FIN numbers. Previous identifiers remain indexed and searchable inside the Google Threat Intelligence (GTI) platform, and GTIG explicitly preserves each cluster's existing MITRE ATT&CK group mapping and other vendors' aliases for cross-reference -- this is a taxonomy/rebranding change, not a new attack, campaign, or technical disclosure, and GTIG itself cautions that because no two organizations share identical visibility into the threat landscape, direct actor-to-actor comparisons across vendor taxonomies remain rarely possible even with aligned second-word categories.

The announcement drew immediate industry commentary. Coverage from SecurityWeek and Help Net Security reported GTIG's own framing that the system is 'intentionally... as simple as possible... to streamline operations and facilitate mapping to other naming taxonomies.' Critical commentary, notably from Mathew J. Schwartz at BankInfoSecurity (July 27, 2026) and CSO Online (July 31, 2026), argued the new schema adds to an already fragmented landscape -- BankInfoSecurity noted that APT44/Sandworm alone already carried at least 13 prior synonyms (including FROZENBARENTS and HADES) before GTIG added a 14th, and cited security researcher Daniel Cuthbert's criticism that the industry 'cannot continue with so many names for the same criminals.' CSO Online argued Google could instead have standardized on one of its own two legacy systems, or adopted an existing external taxonomy (e.g. Microsoft's weather-themed system introduced in 2023), rather than introducing a third. Because this rename directly changes how dozens of well-documented, high-activity threat actors are labeled going forward, it is relevant to any downstream threat intelligence that references these groups by legacy APT/FIN/UNC designations, and to actor-attribution grounding and alias-mapping logic across threat intelligence platforms.

## MITRE ATT&CK

- T1584 Compromise Infrastructure
- T1190 Exploit Public-Facing Application
- T1566 Phishing
- T1195 Supply Chain Compromise
- T1078 Valid Accounts
- T1059 Command and Scripting Interpreter
- T1059.007 Command and Scripting Interpreter: JavaScript
- T1053 Scheduled Task/Job
- T1547 Boot or Logon Autostart Execution
- T1036 Masquerading
- T1027 Obfuscated Files or Information
- T1003 OS Credential Dumping
- T1082 System Information Discovery
- T1021 Remote Services
- T1071 Application Layer Protocol
- T1485 Data Destruction

## Sources

- [Updated Cyber Threat Actor Naming System](https://cloud.google.com/blog/topics/threat-intelligence/updated-cyber-threat-actor-naming-system/)
- [Google changes how it names cyber threat actors](https://www.helpnetsecurity.com/2026/07/27/google-threat-actors-naming-system/)
- [Insane Castle Hurricane: APT Codename Confusion Proliferates](https://www.bankinfosecurity.com/blogs/insane-castle-hurricane-apt-codename-confusion-proliferates-p-4162)
- [Google Adopts New Threat Actor Naming System](https://www.securityweek.com/google-adopts-new-threat-actor-naming-system/)
- [Google creates another set of names for threat actors](https://www.csoonline.com/article/4203952/google-adds-to-confusion-with-new-names-for-threat-actors.html)
- [MITRE ATT&CK Group Profile: APT28](https://attack.mitre.org/groups/G0007/)
- [MITRE ATT&CK Group Profile: APT41](https://attack.mitre.org/groups/G0096/)
- [MITRE ATT&CK Group Profile: FIN7](https://attack.mitre.org/groups/G0046/)
- [MITRE ATT&CK Group Profile: Sandworm Team](https://attack.mitre.org/groups/G0034/)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-2608
