Google’s Top Hacker Hunter Explains Why Cyber Threat Groups Get Codenames

Security 5-8 min read
Google’s Top Hacker Hunter Explains Why Cyber Threat Groups Get Codenames

In the high-stakes world of global cybersecurity, threat actors rarely operate under real names, corporate logos, or official press releases. Instead, they exist as shadowy digital clusters—leaving behind trails of encrypted malware, compromised IP addresses, stolen zero-day exploits, and distinct behavioral signatures across victim networks. To track, analyze, and neutralize these elusive state-sponsored espionage units and cybercrime syndicates, cybersecurity researchers give them memorable codenames.

When news broke that a sophisticated hacking unit breached a government agency or energy grid, headlines blared names like Sandworm, APT41, Cozy Bear, or Volt Typhoon. But why do cybersecurity firms invest so much effort into naming threat groups? How do top hacker hunters at Google, Mandiant, Microsoft, and CrowdStrike turn chaos into order? With Google Threat Intelligence Group unveiling a major overhaul of its threat actor naming taxonomy, Google’s top security researchers are breaking down the science, strategy, and diplomatic nuance behind giving cyber threat groups their unique codenames.

Google’s top cybersecurity researchers explain why threat groups are given distinctive codenames and how these labels help security teams track sophisticated attackers. The article explores the role of naming in identifying, analyzing, and responding to evolving cyber threats.
Google’s top cybersecurity researchers explain why threat groups are given distinctive codenames and how these labels help security teams track sophisticated attackers. The article explores the role of naming in identifying, analyzing, and responding to evolving cyber threats.

1. Why Hackers Get Codenames: The Core Purpose of Threat Taxonomy

To an outsider, giving state-sponsored hackers colorful names might seem like a marketing tactic or an homage to spy novels. However, for threat intelligence analysts and Security Operations Center (SOC) teams, codenames serve as a fundamental operational tool.

Solving the Identification Problem

When an incident response team investigates a breach, they do not initially know the legal identities or home addresses of the individuals sitting behind keyboards thousands of miles away. What they have is a collection of digital artifacts: a specific C2 (Command and Control) server infrastructure, a custom malware strain, a unique phishing template, and a distinct sequence of commands executed during lateral movement inside a network.

By assigning a codename to a specific cluster of activity, researchers create a persistent anchor. This allows analysts across different organizations, continents, and industries to share threat intelligence instantly without needing absolute proof of individual legal identities.

The Speed of Communication During Active Incidents

During a live ransomware outbreak or national security breach, time is the defender's most scarce commodity. If an analyst had to describe an adversary as "the threat actor using custom DLL side-loading on port 443 with spear-phishing lures referencing regional trade summits," coordination would grind to a halt. Saying Sandworm Relic or APT28 instantly communicates a rich catalog of known Tactics, Techniques, and Procedures (TTPs) stored within global threat databases like the MITRE ATT&CK framework.

  • Operational Efficiency: Codenames summarize complex technical profiles into a single, unambiguous label.
  • Pattern Recognition: Helps security tools correlate seemingly isolated intrusion events occurring across different industries.
  • Historical Tracking: Enables threat hunters to trace how an adversary's tooling and targets evolve over years or decades.

2. The Anatomy of Cyber Attribution: From Raw Signals to Confirmed Groups

Assigning a permanent codename to a cyber threat actor is not an arbitrary decision—it is the culmination of a rigorous, multi-stage intelligence process known as cyber attribution.

The UNC Phase: Starting with Uncategorized Activity

Before a hacking group receives a permanent name, it starts life as a temporary tracking cluster. In Mandiant and Google's threat intelligence architecture, these emerging activity clusters are designated as UNC (Uncategorized) groups, followed by a numerical identifier (e.g., UNC1878 or UNC2452).

When a security team observes a new intrusion that doesn't match any known adversary profile, a new UNC bucket is created. Over weeks or months, as analysts collect more data across multiple victim networks, the picture begins to sharpen:

  1. Tooling Overlap: The actor consistently deploys proprietary backdoors or custom zero-day exploits.
  2. Infrastructure Reuse: The actor reuses SSL certificates, registrar accounts, or specific IP subnets for command-and-control operations.
  3. Behavioral Fingerprints: Analysts observe distinct operational hours matching specific time zones, manual command-line typos, or language settings within compiled binaries.

Graduating to Confirmed Threat Actor Status

Once an uncategorized cluster demonstrates high stability, persistent motivation, and clear boundaries separating it from other threat groups, analysts "graduate" the cluster into a formal threat actor profile. This transition represents high-confidence attribution—confirming that the activity represents a coherent, organized team operating with shared objectives.

"Attribution in cyberspace is rarely about finding a signed confession. It is about assembling thousands of technical puzzle pieces until a distinct operational pattern emerges that cannot be plausibly explained by any other group."
— Threat Intelligence Lead, Google Threat Intelligence Group

3. Inside Google's New Unified Cryptonym Taxonomy

A major challenge in threat intelligence has been naming fragmentation. When Google acquired premier cybersecurity firm Mandiant in 2022, it brought together two world-class threat research engines: Mandiant's frontline incident response teams and Google's in-house Threat Analysis Group (TAG).

However, each unit brought its own legacy naming system. Mandiant tracked actors using sequential numbers like APT44 or FIN11, while Google TAG used internal research descriptors. To resolve overlapping names and streamline global reporting, Google Threat Intelligence Group introduced a unified, cryptonym-based naming system.

The Two-Word Naming Formula

Google's unified taxonomy replaces split numeric identifiers with a structured, two-word cryptonym format designed to be memorable, informational, and easy to map across vendor feeds:

  • First Word (Distinctive Identifier): A unique, memorable term often drawn from historical reporting or generated via analyst-verified terms (e.g., Sandworm, ColdRiver, Charming).
  • Second Word (Category Suffix): A standardized suffix that immediately communicates the threat actor's assessed country of origin or primary operating motive.
Category Suffix Assessed Origin / Motive Example Unified Google Name Legacy Identifier
CASTLE China-linked State Espionage Vanguard Castle APT41 / Volt Typhoon alias
RELIC Russia-linked State Espionage Sandworm Relic APT44 / Voodoo Bear alias
ION Iran-linked State Espionage Charming Ion APT35 / Phosphorus alias
NEPTUNE North Korea-linked State Espionage Lazarus Neptune APT38 / Hidden Cobra alias
COMET Financially Motivated Cybercrime Fin Comet FIN7 / Ransomware syndicates

This structured system provides instant context. When a security team reads a report about a threat actor ending in RELIC, they know immediately that the adversary is a state-aligned Russian espionage unit, allowing them to prioritize geopolitical threat models accordingly.

4. The Rosetta Stone: Comparing How Top Security Vendors Name Hackers

Google is not the only major cybersecurity organization tracking global adversaries. Because each vendor develops its own threat intelligence independently based on its specific customer footprint, the industry developed distinct naming themes over time.

CrowdStrike: The Animal Kingdom

CrowdStrike famously categorizes threat groups by pairing a unique descriptor with a nation-state or motive animal:

  • PANDA: China (e.g., Fancy Bear vs Voodoo Bear, Double Dragon Panda)
  • BEAR: Russia (e.g., Cozy Bear, Fancy Bear)
  • KITTEN: Iran (e.g., Charming Kitten)
  • CHOLLIMA: North Korea (e.g., Velvet Chollima)
  • SPIDER: Cybercriminals (e.g., Wizard Spider)

Microsoft: The Weather Forecast

In 2023, Microsoft transitioned from an element/volcano theme to a weather-based taxonomy:

  • Typhoon: China (e.g., Volt Typhoon, Flax Typhoon)
  • Blizzard: Russia (e.g., Star Blizzard, Midnight Blizzard)
  • Sandstorm: Iran (e.g., Peach Sandstorm)
  • Sleet: North Korea (e.g., Ruby Sleet)
  • Tempest: Financially motivated cybercrime (e.g., Strawberry Tempest)

Joint Mapping Initiatives

To reduce industry confusion, major threat intelligence providers—including Google, Microsoft, CrowdStrike, and Palo Alto Networks Unit 42—actively participate in joint mapping initiatives and contribute to public frameworks like MITRE ATT&CK. These mapping tables allow enterprise security tools to translate between vendor labels seamlessly, ensuring that whether a system alerts on Sandworm Relic, Seashell Blizzard, or Voodoo Bear, defenders recognize they are dealing with the exact same military intelligence unit.

5. Glamour vs. Sobriety: The Ethics and Diplomacy of Hacker Names

How security firms name hackers is not without debate. Researchers frequently wrestle with a subtle psychological challenge: avoiding giving cybercriminals cool or glorified titles that feed adversary egos.

Avoiding the 'Cool Hacker' Trap

In the early days of cybersecurity, names like Dark Avenger or Cyber Ninja risked heroizing malicious actors in underground forums. Modern intelligence firms deliberately choose sober, functional, or randomized codenames to avoid glorifying criminal activity.

"We use structured, sober taxonomy because cybersecurity is not an action movie. Our goal is to strip away the mystique of threat actors and treat them as operational problems to be analyzed, tracked, and dismantled."
— Jamie Collier, Senior Threat Intelligence Advisor

Navigating Political and Diplomatic Sensitivity

Publicly accusing a foreign sovereign nation of state-sponsored cyber espionage carries serious geopolitical and diplomatic weight. Private cybersecurity firms must carefully balance technical attribution against political commentary.

By using category suffixes like CASTLE or weather indicators like Typhoon, threat intelligence reports can communicate an assessed geographical connection based on technical evidence (such as language, time zone activity, and infrastructure location) without making formal legal or diplomatic declarations on behalf of governments.

6. Practical Takeaways for Enterprise Defenders

For enterprise Security Operations Centers (SOCs) and Chief Information Security Officers (CISOs), understanding threat actor codenames provides direct operational value:

  1. Cross-Feed Correlation: Use vendor mapping tables to consolidate threat feeds from Google, Microsoft, and CrowdStrike into a single alert pipeline.
  2. Prioritize Threat Models: Identify which threat actor categories (e.g., COMET for ransomware vs. CASTLE for IP theft) present the highest risk to your specific industry sector.
  3. Automate YARA & Sigma Rules: Map incoming Indicators of Compromise (IOCs) directly to MITRE ATT&CK group profiles to trigger automated endpoint detection and response (EDR) playbooks.
  4. Track Threat Evolution: Monitor UNC clusters to catch emerging zero-day campaigns before they graduate into widespread commercial threats.

Key Takeaways

  • Unified Google Taxonomy: Google Threat Intelligence Group introduced a standardized two-word cryptonym system merging Mandiant and Google TAG tracking.
  • Category Suffixes: Uses clear suffixes like CASTLE (China), RELIC (Russia), ION (Iran), NEPTUNE (North Korea), and COMET (Cybercrime) for instant threat context.
  • The Attribution Journey: Threat activity begins as temporary UNC (Uncategorized) clusters before graduating to full threat actor profiles after rigorous analysis.
  • Industry Translation: Major security vendors participate in joint mapping efforts to connect Google cryptonyms, CrowdStrike animal names, and Microsoft weather terms to MITRE ATT&CK identifiers.

Related Topics: #GoogleSecurity #Mandiant #CyberThreatIntel #ThreatAttribution #Cybersecurity2026 #MITREATTACK #InfoSec #TechSecurity