Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Critical Vulnerabilities Patched With Chrome 151 Update

    August 8, 2026

    T. Rowe Price defends memecoin exposure in new crypto ETF, calling it a blockchain ‘stress test’

    August 8, 2026

    From small cats to pangolins: Detection dogs help track elusive species

    August 8, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Critical Vulnerabilities Patched With Chrome 151 Update
    • T. Rowe Price defends memecoin exposure in new crypto ETF, calling it a blockchain ‘stress test’
    • From small cats to pangolins: Detection dogs help track elusive species
    • UAE says Iran targeted ADNOC tanker in Strait of Hormuz, no casualties | US-Israel war on Iran News
    • Senate passes Russia sanctions bill
    • Amid Abuse Claims Against Max Miller, This Democrat Thinks He Can Win His Seat
    • Nicola Sturgeon ‘has not spoken to’ estranged husband, Peter Murrell, since he was jailed | Nicola Sturgeon
    • Google’s top hacker hunter explains why hacking groups get codenames
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Saturday, August 8
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Technology

    Google’s top hacker hunter explains why hacking groups get codenames

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKAugust 8, 2026 Technology No Comments4 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    For more than a decade, the cybersecurity industry has been assigning names to different hacking groups. Some of them, like Fancy Bear, have crossed over into the mainstream because of their prominent hacks and memorable names. Others are only known within the cybersecurity industry. 

    Oftentimes, even industry insiders can’t keep track. In part, that’s because every company names hacking groups differently. That’s why there are resources like this one, which attempt to be a one-stop shop where cybersecurity professionals, government officials, policymakers, journalists, and the wider public can make sense of who is who. 

    Last month, Google became the latest company to revamp its naming system for hacking groups.

    Gone are the days APT1, APT41 or APT whatever number, which was the system adopted by Mandiant, once an independent security firm that’s now part of Google. Mandiant was the first to adopt a naming scheme.

    From now on, Google’s system is relatively simple: A hacking group will have a first name that is memorable and random, and a second word whose initial indicates the country of origin: Castle for China, Ion for Iran, Neptune for North Korea, and Relic for Russia.

    According to Shane Huntley, the chief technology officer of Google Threat Intelligence Group, the company’s in-house hacker hunting team, the revamp was necessary to bring clarity to security researchers both inside the company and externally. 

    In the early 2010s, when companies started publishing reports on cyberattacks and naming the hackers behind them, Huntley told TechCrunch that, “we were not expecting to have as many threat groups as we do today.”

    It had become hard to keep track of everyone. Google now tracks more than 5,000 “activity clusters” in several countries, according to John Hultquist, chief analyst at Google Threat Intelligence Group. Huntley said that there are very few developed nations that don’t have their own cyber capabilities and hacking groups. 

    But what is the point of naming hacking groups? It’s not just an academic exercise, Huntley explained. The goal is to have a baseline understanding of who is attacking who, and how they are attacking them. That way organizations can recognize threats more quickly, prepare against them, ideally stop them, or at least investigate incidents more promptly. 

    All that, he said, it’s possible only if you name the hackers and track them consistently. 

    “If you actually get hacked by them or you’re dealing with some incident, knowing how that actor behaves, what they do, what they’ve done in the past, all of these details become critically important to help the response and also work out your coverage against these threats as well,” said Huntley.

    Knowing how the North Korean government hackers known as the Lazarus Group behaves, what their goals usually are, and who they work for, gives defenders a starting point in dealing with these hackers. 

    Tracking state-sponsored hackers, while challenging, is easier than tracking cybercriminal groups and hackers-for-hire, Huntley explained. The government hackers tend to have more consistent targets and activities, while cybercriminal groups have members that come and go, sometimes splinter, and otherwise are more amorphous. Hacker-for-hire groups and spyware makers tend to have a lot of customers in different parts of the world, making them slightly harder to track. 

    A common criticism whenever a new naming system gets announced is: Why don’t all companies and organizations just use the same codenames? While that seems like an easy question to answer, the reality is that every company has a slightly different view of every group, based on their own sets of data and telemetry. Huntely said this is an inescapable reality that can’t be avoided just by sharing more information among companies and groups of researchers. 

    “No one has perfect visibility,” he said. “We are building our model and our best understanding, but we will never know everything about what’s going on.”

    By unifying the naming scheme of Google’s old Threat Analysis Group, which Huntely headed, and Mandiant, at least now there’s one fewer scheme to remember. For everything else, refer to this gargantuan list.

    When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.

    codenames explains Googles Groups Hacker hacking hunter top
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Census Proposal Would Stop Counting Undocumented Immigrants—and Ignore Race and Sexual Orientation

    Is football AI-proof? Why tech investors wanted a slice of the World Cup

    Here Are the First Images of the Crater Left on the Moon by SpaceX’s Rocket

    Déjà Vu? Meta’s AI Escapes Testing Lab in Hacking Joyride

    Best Gaming Laptops (2026): Razer, Asus, Dell, and More

    Nitecore’s latest power bank is the lightest and most compact yet

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Critical Vulnerabilities Patched With Chrome 151 Update

    August 8, 2026

    T. Rowe Price defends memecoin exposure in new crypto ETF, calling it a blockchain ‘stress test’

    August 8, 2026

    From small cats to pangolins: Detection dogs help track elusive species

    August 8, 2026

    UAE says Iran targeted ADNOC tanker in Strait of Hormuz, no casualties | US-Israel war on Iran News

    August 8, 2026
    Latest Posts

    With Hopes High for New H.I.V. Prevention Pill, Merck Takes Steps to Ensure Access

    July 24, 2026

    Trump to speak at rescheduled White House Correspondents’ Dinner following failed April shooting

    July 24, 2026

    When is an apology not an apology? When it comes from an AI boss with an out-of-control chatbot | Marina Hyde

    July 24, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Critical Vulnerabilities Patched With Chrome 151 Update

    August 8, 2026

    T. Rowe Price defends memecoin exposure in new crypto ETF, calling it a blockchain ‘stress test’

    August 8, 2026

    From small cats to pangolins: Detection dogs help track elusive species

    August 8, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.