{"id":256353,"date":"2026-08-08T15:00:00","date_gmt":"2026-08-08T15:00:00","guid":{"rendered":"https:\/\/entertainment.runfyers.com\/index.php\/2026\/08\/08\/googles-top-hacker-hunter-explains-why-hacking-groups-get-codenames-techcrunch\/"},"modified":"2026-08-08T15:00:00","modified_gmt":"2026-08-08T15:00:00","slug":"googles-top-hacker-hunter-explains-why-hacking-groups-get-codenames-techcrunch","status":"publish","type":"post","link":"https:\/\/entertainment.runfyers.com\/index.php\/2026\/08\/08\/googles-top-hacker-hunter-explains-why-hacking-groups-get-codenames-techcrunch\/","title":{"rendered":"Google&#8217;s top hacker hunter explains why hacking groups get codenames | TechCrunch"},"content":{"rendered":"<p> <br \/>\n<\/p>\n<div>\n<p id=\"speakable-summary\" class=\"wp-block-paragraph\">For more than a decade, the cybersecurity industry has been assigning names to different hacking groups. Some of them, like <a rel=\"nofollow noopener\" href=\"https:\/\/attack.mitre.org\/groups\/G0007\" target=\"_blank\">Fancy Bear<\/a>, have crossed over into the mainstream because of their prominent hacks and memorable names. Others are only known within the cybersecurity industry.\u00a0<\/p>\n<p class=\"wp-block-paragraph\">Oftentimes, even industry insiders can\u2019t keep track. In part, that\u2019s because every company names hacking groups differently. That\u2019s why there are resources like <a rel=\"nofollow noopener\" href=\"https:\/\/attack.mitre.org\/groups\/\" target=\"_blank\">this one<\/a>, which attempt to be a one-stop shop where cybersecurity professionals, government officials, policymakers, journalists, and the wider public can make sense of who is who.\u00a0<\/p>\n<p class=\"wp-block-paragraph\">Last month, Google became the latest company to <a rel=\"nofollow noopener\" href=\"https:\/\/cloud.google.com\/blog\/topics\/threat-intelligence\/updated-cyber-threat-actor-naming-system\" target=\"_blank\">revamp its naming system<\/a> for hacking groups. <\/p>\n<p class=\"wp-block-paragraph\">Gone are the days APT1, APT41 or APT <em>whatever number<\/em>, which was the system adopted by Mandiant, once an independent security firm that\u2019s now part of Google. Mandiant was the first to adopt a naming scheme. <\/p>\n<p class=\"wp-block-paragraph\">From now on, Google\u2019s system is relatively simple: A hacking group will have a first name that is memorable and random, and a second word whose initial indicates the country of origin: Castle for China, Ion for Iran, Neptune for North Korea, and Relic for Russia.<\/p>\n<p class=\"wp-block-paragraph\">According to Shane Huntley, the chief technology officer of Google Threat Intelligence Group, the company\u2019s in-house hacker hunting team, the revamp was necessary to bring clarity to security researchers both inside the company and externally.\u00a0<\/p>\n<p class=\"wp-block-paragraph\">In the early 2010s, when companies started publishing reports on cyberattacks and naming the hackers behind them, Huntley told TechCrunch that, \u201cwe were not expecting to have as many threat groups as we do today.\u201d<\/p>\n<p class=\"wp-block-paragraph\">It had become hard to keep track of everyone. Google now tracks more than 5,000 \u201cactivity clusters\u201d in several countries, according to John Hultquist, chief analyst at Google Threat Intelligence Group. Huntley said that there are very few developed nations that don\u2019t have their own cyber capabilities and hacking groups.\u00a0<\/p>\n<p class=\"wp-block-paragraph\">But what is the point of naming hacking groups? It\u2019s not just an academic exercise, Huntley explained. The goal is to have a baseline understanding of who is attacking who, and how they are attacking them. That way organizations can recognize threats more quickly, prepare against them, ideally stop them, or at least investigate incidents more promptly.\u00a0<\/p>\n<p class=\"wp-block-paragraph\">All that, he said, it\u2019s possible only if you name the hackers and track them consistently.\u00a0<\/p>\n<p class=\"wp-block-paragraph\">\u201cIf you actually get hacked by them or you\u2019re dealing with some incident, knowing how that actor behaves, what they do, what they\u2019ve done in the past, all of these details become critically important to help the response and also work out your coverage against these threats as well,\u201d said Huntley.<\/p>\n<p class=\"wp-block-paragraph\">Knowing how the North Korean government hackers known as the <a rel=\"nofollow noopener\" href=\"https:\/\/attack.mitre.org\/groups\/G0032\/\" target=\"_blank\">Lazarus Group<\/a> behaves, what their goals usually are, and who they work for, gives defenders a starting point in dealing with these hackers.\u00a0<\/p>\n<p class=\"wp-block-paragraph\">Tracking state-sponsored hackers, while challenging, is easier than tracking cybercriminal groups and hackers-for-hire, Huntley explained. The government hackers tend to have more consistent targets and activities, while cybercriminal groups have members that come and go, sometimes splinter, and otherwise are more amorphous. Hacker-for-hire groups and spyware makers tend to have a lot of customers in different parts of the world, making them slightly harder to track.\u00a0<\/p>\n<p class=\"wp-block-paragraph\">A common criticism whenever a new naming system gets announced is: Why don\u2019t all companies and organizations just use the same codenames? While that seems like an easy question to answer, the reality is that every company has a slightly different view of every group, based on their own sets of data and telemetry. Huntely said this is an inescapable reality that can\u2019t be avoided just by sharing more information among companies and groups of researchers.\u00a0<\/p>\n<p class=\"wp-block-paragraph\">\u201cNo one has perfect visibility,\u201d he said. \u201cWe are building our model and our best understanding, but we will never know everything about what\u2019s going on.\u201d<\/p>\n<p class=\"wp-block-paragraph\">By unifying the naming scheme of Google\u2019s old Threat Analysis Group, which Huntely headed, and Mandiant, at least now there\u2019s one fewer scheme to remember. For everything else, <a rel=\"nofollow noopener\" href=\"https:\/\/attack.mitre.org\/groups\/\" target=\"_blank\">refer to this gargantuan list<\/a>.<\/p>\n<\/div>\n<p><em>When you purchase through links in our articles, <a href=\"https:\/\/techcrunch.com\/techcrunch-affiliate-monetization-standards\/\" target=\"_blank\" rel=\"noopener\">we may earn a small commission<\/a>. This doesn\u2019t affect our editorial independence.<\/em><\/p>\n<p><br \/>\n<br \/><a href=\"https:\/\/techcrunch.com\/2026\/08\/08\/googles-top-hacker-hunter-explains-why-hacking-groups-get-codenames\/\" target=\"_blank\" rel=\"noopener\">Source link <\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>For more than a decade, the cybersecurity industry has been assigning names to different hacking groups. Some of them, like Fancy Bear, have crossed over into the mainstream because of their prominent hacks and memorable names. Others are only known within the cybersecurity industry.\u00a0 Oftentimes, even industry insiders can\u2019t keep track. In part, that\u2019s because [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":256354,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[14],"tags":[],"class_list":{"0":"post-256353","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-tech"},"_links":{"self":[{"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/posts\/256353","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/comments?post=256353"}],"version-history":[{"count":0,"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/posts\/256353\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/media\/256354"}],"wp:attachment":[{"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/media?parent=256353"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/categories?post=256353"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/tags?post=256353"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}