Loading...
Why are hacking groups given codenames?
Last month, Google changed its naming convention for hacking groups

Why are hacking groups given codenames?

Aug 09, 2026
10:59 am

What's the story

The cybersecurity industry has been naming different hacking groups for over a decade. Some, like Fancy Bear, have become household names due to their high-profile hacks and catchy monikers. However, others remain obscure within the cybersecurity community. The problem is further complicated by the fact that each company has its own naming convention for these groups. So, why are they given codenames? Let's find out.

Naming overhaul

Google's approach to naming hacking groups

Last month, Google changed its naming convention for hacking groups. The tech giant ditched the APT1, APT41 or APT _whatever number_ system used by Mandiant, a former independent security firm and now part of Google.

System breakdown

Breaking down the new naming system

Under Google's new naming system, the first name is random and memorable. The second word's initial indicates the hacker group's country of origin.

For instance, "Castle" stands for China, "Ion" for Iran, "Neptune" for North Korea, and "Relic" for Russia.

This simplified approach is aimed at making it easier for security researchers both within and outside Google to understand these groups better.

ADVERTISEMENT

System necessity

Why the revamp was necessary

Shane Huntley, Google's Threat Intelligence Group CTO, said the revamp was necessary to bring clarity to security researchers.

He explained that when companies started publishing reports on cyberattacks and naming hackers in the early 2010s, they didn't expect as many threat groups as we have today.

Now, Google tracks over 5,000 "activity clusters" across multiple countries.

ADVERTISEMENT

Purpose explained

The importance of naming in cybersecurity

Huntley emphasized that naming hacking groups isn't just an academic exercise. The main goal is to have a baseline understanding of who is attacking whom and how.

This way, organizations can identify threats faster, prepare against them, ideally stop them or at least investigate incidents more promptly.

He said knowing the behavior and past actions of a hacker becomes critical in responding to an incident effectively.

Tracking challenges

Insights on tracking hackers

Huntley said tracking state-sponsored hackers is easier than tracking cybercriminal groups and hackers-for-hire.

This is because government hackers tend to have more consistent targets and activities, while members of cybercriminal groups can come and go, sometimes splintering off.

Hacker-for-hire groups and spyware makers usually have many customers worldwide, making them a bit harder to track.

ADVERTISEMENT