Google has a new way of talking about the latest cyber threats — so get ready for a whole load of crazy new names
- Google Threat Intelligence Group is replacing its inherited Mandiant and TAG identifiers with two-word cryptonyms, starting with several dozen of its most-tracked groups
- The second word encodes attribution or motive, with CASTLE for China, ION for Iran, NEPTUNE for North Korea, RELIC for Russia, and COMET for criminal crews not visibly tied to a particular country
- The scheme standardizes naming inside Google but adds another convention to an industry that agreed on a shared alias mapping only last year
The Russian military intelligence crew that most of the security industry knows as Sandworm has picked up another name – it is Sandworm Relic, at least when Google is doing the talking.
Google Threat Intelligence Group has announced plans to retire the tangle of identifiers it inherited from two separate teams and replacing them with two-word cryptonyms, starting with several dozen of the groups it tracks most closely and continuing on a rolling basis.
Google has recently argued against its old approach of using sequential identifiers like APT1, on the grounds that a number tells a defender nothing about who they are dealing with. It has begun replacing them with a schema it says is more intuitive and makes it easier to determine where an attack comes from and what motivates it.
Latest Videos FromTechRadar
Rationalizing Google’s need to change an already-established order
The mechanics are simple enough. Every tracked actor gets a pair of words. The first is meant to be distinctive and memorable, and where the security community has already settled on a moniker, Google says it will keep it. Where no such term exists, the word is generated at random to remove bias, then checked by analysts before it goes into use.
The second word does the categorizing, sorting clusters by motivation, attribution or activity type. The sample table Google published maps CASTLE to groups tied to the People’s Republic of China, ION to Iran, NEPTUNE to North Korea, RELIC to Russia and COMET to financially motivated criminals.
The approach, as CyberScoop points out, closely echoes CrowdStrike’s long-running practice of pairing a unique term with an animal keyed to country or motive: PANDA for China, BEAR for Russia, SPIDER for criminals, JACKAL for hacktivists. Google has simply swapped the animals for words like CASTLE and NEPTUNE.
The move is the latest step after Google announced its $5.4 billion acquisition of Mandiant in 2022, which it eventually combined with its in-house Threat Analysis Group to form GTIG.
Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!
The merger brought together two tracking systems that had evolved independently for years, meaning the same activity could appear under two different Google labels depending on which team wrote the report.
For now, Russia-linked Sandworm Relic is the only new name to have surfaced publicly, and Google is hardly the first to attempt this.
Microsoft has settled on weather, and countries such as China have publicly disputed the attributions sitting behind those labels. Google’s move to “streamline” threat names could still make things simpler if it catches on with the rest of the world.
Alternatively, it could just add to the confusion in an industry where no standards are yet completely agreed upon. Google and Mandiant signed on to a Microsoft and CrowdStrike alias-mapping effort in June 2025, and The Register reported that sources at the time indicated both were keen to adopt the Microsoft-led scheme. Last week’s announcement makes no mention of it. However good Google’s intentions, defenders are still being handed one more system to learn.

Follow TechRadar on Google News and add us as a preferred source to get our expert news, reviews, and opinion in your feeds.
Source
Google Threat Intelligence Group is replacing its inherited Mandiant and TAG identifiers with two-word cryptonyms, starting with several dozen of its most-tracked groups The second word encodes attribution or motive, with CASTLE for China, ION for Iran, NEPTUNE for North Korea, RELIC for Russia, and COMET for criminal crews not…
Recent Posts
- Nike Promo Codes and Discounts: 30% for August 2026
- How to watch Women’s Open 2026: Free Live Streams, TV Channels & Preview
- Verizon scores $1 billion Google deal to connect its data centers to dark fiber – but is this only the beginning?
- I built a personal Netflix in three hours using the free Plex app — and I’m convinced it’s the future for Blu-ray and DVD fans
- ‘Exceptional espresso every time’: The KitchenAid KF3 is a gorgeous fully automatic coffee machine ideal for smaller kitchens
Archives
- July 2026
- June 2026
- May 2026
- April 2026
- March 2026
- February 2026
- January 2026
- December 2025
- November 2025
- October 2025
- September 2025
- August 2025
- July 2025
- June 2025
- May 2025
- April 2025
- March 2025
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023
- August 2023
- July 2023