Google's top hacker hunter explains why hacking groups get codenames
Google's top hacker hunter explains why hacking groups get codenames. The company has revamped its naming system for hacking groups, making it easier for security researchers to track and understand who is behind cyberattacks.
Intelligence analysis by Llama

Google's top hacker hunter explains why hacking groups get codenames. The company has revamped its naming system for hacking groups, making it easier for security researchers to track and understand who is behind cyberattacks. The new system uses a first name that is memorable and random, and a second word whose initial indicates the country of origin.
Imagine you're trying to catch a bad guy, but you don't know who he is or what he looks like. That's kind of like what happens when hackers attack a company or organization. To make it easier to catch the bad guys, Google has created a new system to name different hacking groups. It's like giving them a nickname, so we can keep track of who's who and what they're doing.
Analysis
Google's New Naming System for Hacking Groups: A Breakdown of the Changes
Google's top hacker hunter, Shane Huntley, explained that the company's old naming system for hacking groups was becoming increasingly complex and hard to track. The new system, which was announced last month, is designed to bring clarity to security researchers both inside the company and externally.
The new system uses a first name that is memorable and random, and a second word whose initial indicates the country of origin. For example, a hacking group from China might be called 'Castle', while a group from Iran might be called 'Ion'. This system is relatively simple and easy to understand, making it easier for security researchers to track and understand who is behind cyberattacks.
But why is it so important to name hacking groups? According to Huntley, the goal is to have a baseline understanding of who is attacking who, and how they are attacking them. This can help organizations recognize threats more quickly, prepare against them, ideally stop them, or at least investigate incidents more promptly.
The new naming system is also designed to help track state-sponsored hackers, who tend to have more consistent targets and activities. Cybercriminal groups and hackers-for-hire, on the other hand, are harder to track because their members come and go, sometimes splinter, and otherwise are more amorphous.
A common criticism of naming systems is that all companies and organizations should just use the same codenames. However, Huntley explained that this is an inescapable reality that can't be avoided just by sharing more information among companies and groups of researchers.
'No one has perfect visibility,' he said. 'We are building our model and our best understanding, but we will never know everything about what's going on.'
By unifying the naming scheme of Google's old Threat Analysis Group and Mandiant, at least now there's one fewer scheme to remember. For everything else, refer to this gargantuan list.
Key points
- Google has revamped its naming system for hacking groups, making it easier for security researchers to track and understand who is behind cyberattacks.
- The new system uses a first name that is memorable and random, and a second word whose initial indicates the country of origin.
- The goal of the new system is to have a baseline understanding of who is attacking who, and how they are attacking them.
- The new system is designed to help track state-sponsored hackers, who tend to have more consistent targets and activities.
The new naming system for hacking groups could lead to better collaboration and information sharing among security researchers and organizations. This could result in more effective threat detection and response, and ultimately, a safer online environment.
The new naming system may not be enough to stop the rise of cybercrime and hacking groups. These groups are constantly evolving and adapting, making it difficult to keep track of them. Additionally, the lack of perfect visibility into the world of hacking groups means that there will always be some level of uncertainty and risk.



