Google Threat Intelligence Group has retired its inherited system of sequential threat actor identifiers, replacing them with two-word cryptonyms designed to make attack attribution more intuitive. The new naming scheme, which assigns each tracked group a unique first word and a second word encoding its origin or motive, marks a major shift in how the company labels cyber threats.
Mechanics of the New Naming Scheme
Every tracked actor now receives a pair of words. The first word is designed to be distinctive and memorable. Where the security community has already settled on a moniker, Google says it will keep that name. Where no such term exists, the word is generated at random to remove bias, then checked by analysts before it goes into use.
The second word does the categorizing. It sorts clusters by motivation, attribution or activity type. The mapping is as follows:
The approach closely echoes CrowdStrike's long-running practice of pairing a unique creature name with an animal keyed to country or motive. Google has replaced animals with words like CASTLE and NEPTUNE. The first publicly visible example is Sandworm Relic, the Russian military intelligence crew previously known as Sandworm.
Why This Matters
This change directly affects how security teams interpret threat intelligence from Google. The old system of APT-style numbers told defenders nothing about who was behind an attack. The new cryptonyms aim to fix that by embedding attribution into the label itself. A defender who sees "RELIC" in a report instantly knows the activity likely originates from Russia.
But the real-world impact depends on adoption. Google Threat Intelligence Group is one of the largest threat intelligence providers, but the industry already has multiple competing naming conventions. Microsoft uses weather-themed names. CrowdStrike uses animals. The United States government uses yet another system. Google's move could streamline internal operations but it also adds another layer of terminology that defenders must learn.
For organizations that rely on Google's threat intelligence, the new names will eventually become the standard in Google's reports and tools. Analysts will need to update their internal tracking systems and cross-reference old identifiers. The transition period may cause confusion as legacy names coexist with new ones.
Industry Fragmentation Persists
Google's announcement comes after years of efforts to unify threat actor naming. In June 2025, Google and Mandiant signed on to a Microsoft and CrowdStrike-led alias mapping effort. Sources at the time indicated both companies were keen to adopt the Microsoft-led scheme. However, last week's announcement makes no mention of that framework.
This creates a situation where even well-intentioned improvements can add to the confusion. The Russian military group Sandworm now has at least three names: Sandworm, Sandworm Relic and whatever other vendors call it. While Google's system is more informative than APT1, it is yet another system in a field that agreed on a shared alias mapping only last year. The success of the new cryptonyms will depend on whether other threat intelligence firms adopt them or stick with their own conventions.
Google Threat Intelligence Group formed after the $5.4 billion acquisition of Mandiant in 2022, merging Mandiant's tracking with Google's in-house Threat Analysis Group. The merger brought together two independent tracking systems, meaning the same activity could appear under two different Google labels. The new naming scheme is a direct response to that internal fragmentation.
For now, Sandworm Relic is the only new name to have surfaced publicly. Google plans to roll out additional cryptonyms on a rolling basis. Whether the industry follows remains an open question.



