Google’s New Hacker Codenames: How China & Iran’s Groups Get Secret Names (2026)

The world of cybersecurity is a complex and ever-evolving landscape, and one intriguing aspect is the naming of hacking groups. In this article, we delve into the recent changes made by Google, a leading tech giant, and explore the reasons behind their unique approach to naming these groups.

The Evolution of Hacking Group Names

For over a decade, the cybersecurity industry has been assigning names to hacking groups, with some, like Fancy Bear, becoming household names due to their high-profile hacks. However, keeping track of these groups has been a challenge, as every company seems to have its own naming system.

Google, in an effort to bring clarity to the chaos, has revamped its naming system for hacking groups. The previous system, adopted from Mandiant, used a numerical approach with names like APT1 and APT41. But Google has now simplified things with a more memorable and random first name, followed by a second word indicating the country of origin. For example, Castle for China, Ion for Iran, and so on.

A Chat with Google's Top Hacker Hunter

Shane Huntley, the chief technology officer of Google Threat Intelligence Group, explains that this revamp was necessary to provide a clear understanding of who is attacking whom and how. He highlights the importance of naming hackers consistently, as it enables organizations to recognize threats, prepare for them, and investigate incidents more efficiently.

Huntley emphasizes that naming hacking groups is not just an academic exercise but a crucial step in defending against cyber threats. By understanding the behavior, goals, and affiliations of these groups, defenders can gain a strategic advantage.

The Challenge of Tracking Hackers

Tracking state-sponsored hackers is a challenging task, but it is made easier by their consistent targets and activities. In contrast, cybercriminal groups and hackers-for-hire are more fluid, with members coming and going, making them harder to pin down.

One common question arises: Why can't all companies use the same codenames? Huntley explains that this is an inescapable reality due to the unique data and telemetry each company possesses. No one has perfect visibility, and while sharing information can help, it won't eliminate these differences entirely.

A Step Towards Clarity

By unifying the naming schemes of Google's Threat Analysis Group and Mandiant, Google has taken a step towards simplifying the landscape. While there's still a long list of hacking groups to keep track of, this move brings a much-needed clarity to the cybersecurity community.

In my opinion, this initiative by Google showcases their commitment to enhancing cybersecurity practices. It's a fascinating insight into the world of cyber defense and the ongoing battle against malicious hacking groups.

Google’s New Hacker Codenames: How China & Iran’s Groups Get Secret Names (2026)
Top Articles
Latest Posts
Recommended Articles
Article information

Author: Margart Wisoky

Last Updated:

Views: 6161

Rating: 4.8 / 5 (78 voted)

Reviews: 93% of readers found this page helpful

Author information

Name: Margart Wisoky

Birthday: 1993-05-13

Address: 2113 Abernathy Knoll, New Tamerafurt, CT 66893-2169

Phone: +25815234346805

Job: Central Developer

Hobby: Machining, Pottery, Rafting, Cosplaying, Jogging, Taekwondo, Scouting

Introduction: My name is Margart Wisoky, I am a gorgeous, shiny, successful, beautiful, adventurous, excited, pleasant person who loves writing and wants to share my knowledge and understanding with you.