"intentionally seeking to keep this system as simple as possible to streamline operations and facilitate mapping to other naming taxonomies," Google wrote — and then it decided to name the crews itself.
Google, Mandiant and the formation of CTIG
Google announced a new taxonomy after its 2022 acquisition of Mandiant and the subsequent incorporation of that business into a new team called the Google Threat Intelligence Group (CTIG). The company framed the move as a response to the combined team's need for "consistent naming conventions to describe cybercrime crews" now that "two have become one."
The two-word naming schema Google will use
Google's scheme is explicitly two words. The first word, the company says, "is a unique and memorable term chosen to represent the specific actor." If security practitioners have already applied a particular moniker, Google will reuse it; if not, the company will randomly generate a word "to remove bias." The second word "categorizes threat clusters by motivation, attribution, or activity type based on which category we consider to be most important for defense and response strategies."
The names Google has chosen and what they map to
- CASTLE — crews from the People's Republic of China
- ION — threats from Iran
- NEPTUNE — North Korean attackers
- RELIC — Russians
- COMET — cybercrims who aren't backed by a state
Naming fragmentation and the Microsoft–CrowdStrike effort
Google acknowledged other industry players maintain their own naming schemas, describing its approach as intentionally simple to "facilitate mapping to other naming taxonomies." That stance comes against a backdrop in which multiple naming systems already coexist: in 2025 Microsoft and CrowdStrike tried to spark an industry-wide effort to apply consistent names to threat actors.
The practical consequence has been duplication and confusion. Researchers, the post notes, sometimes refer to the same group by many names — for example, the cluster of labels Seashell Blizzard, IRIDIUM, VOODOO BEAR, BE2, UAC-0113, Blue Echidna, PHANTOM, BlackEnergy Lite, and APT44 have all been used to refer to the same entity, Russia's Military Intelligence Unit 74455. With organizations using multiple security tools and receiving intelligence from multiple vendors, the result is that "users must try to understand which crews they're trying to defend against."
How technologists, procurement leaders, and adversaries are likely to react
- Technologists and security teams: Google frames its design to streamline operations and make mapping to other taxonomies possible; security teams will therefore be watching how Google maps existing monikers and whether the random-word option indeed reduces perceived bias.
- Affected enterprises and procurement leaders: Firms that consume threat intelligence from multiple vendors face the bookkeeping task the post describes — reconciling names across tools and feeds so defenders can "understand which crews they're trying to defend against."
- Adversaries and national authorities: The taxonomy sits amid prior complaints about labeling: in 2024 China's National Computer Virus Emergency Response Center (CVERC) objected to western companies using names such as "Typhoon," "Panda," or "Dragon" for Chinese groups and suggested alternatives like "Hurricane" or "Koala." The Register's post notes that "Koala" is a word from the language spoken by the Darug people and cautions the animal's sleepy habits may not spur defenders to action.
Google's move formalizes a simple, repeatable approach to naming but does not, on its face, resolve the deeper problem: multiple vendors have long developed independent schemas and, despite a 2025 push from Microsoft and CrowdStrike, a single, adopted taxonomy has not emerged. Google says it wants to make mapping easier; whether vendors and consumers will converge around the CTIG labels, reuse existing monikers, or continue to live with multiplicity is the immediate question left on the table.




