"Threat tracking shouldn’t be an exercise in memorization, but rather one of intuition," the post reads.
Google Threat Intelligence Group’s unified two-word code names
Last week Google Threat Intelligence Group announced a new naming approach that replaces years of internal split systems with a single set of two-word code names. The change merges the naming systems that had diverged inside Google after the company acquired Mandiant in 2022 and combined it with its Threat Analysis Group, the post says. Google’s rollout begins with several dozen of the most actively tracked hacking groups and will expand over time. Older names will remain searchable inside Google’s threat intelligence platform, where they will also be mapped to the MITRE ATT&CK framework and to naming systems used by other vendors.
How the two-word names are constructed
Each tracked group gets a two-word name. The first word is a distinctive, easy-to-remember term — often taken from names already used in past reporting about that group; when no prior name exists, researchers will generate one at random and have analysts check it before use. The second word sorts the group by category such as country of origin or motive. Google published examples that pair CASTLE with groups tied to China, ION with Iran, NEPTUNE with North Korea, RELIC with Russia, and COMET with financially motivated threat actors not tied to a nation-state. Google also says groups will carry the label "UNC" (for uncategorized) if it is still too early to place the group within the taxonomy.
Why the structure echoes CrowdStrike’s naming logic
The new system mirrors the basic logic CrowdStrike has long used: a specific term plus a second element that signals country or motive. CrowdStrike pairs a specific term with an animal label tied to country or motive — PANDA for China, BEAR for Russia, SPIDER for cybercriminals and JACKAL for hacktivists. Google replaces animals with evocative words like CASTLE and NEPTUNE but adheres to the same argument: a two-part name carries more information than a bare country label or a number, and it can be adjusted as attribution is refined.
Microsoft’s weather names and the industry backlash
Google’s change arrives after several other vendors reworked their naming conventions. In April 2023 Microsoft abandoned a system built on chemical elements, trees and volcanoes in favor of weather terms, using Typhoon to mark China, Blizzard for Russia, Sandstorm for Iran and Tempest for financially motivated cybercriminals. The switch produced memorable pairings — among them Strawberry Tempest, Pumpkin Sandstorm and Pistachio Tempest — and prompted pushback from some industry experts who said the names compared tracked groups to ice cream flavors or cocktails.
Microsoft and CrowdStrike’s June 2025 mapping effort, and what it means for CISOs, procurement leaders, and vendors
By 2025 naming sprawl had become a shared operational headache. In June of that year Microsoft and CrowdStrike announced a joint mapping effort that pairs Microsoft’s weather names with CrowdStrike’s animal names for the same tracked groups; Google, Mandiant and Palo Alto Networks Unit 42 signed on to contribute. For CISOs and security teams, the immediate implication is practical: the competing label sets will remain in circulation, but new and older labels will be linked and searchable so analysts can translate across vendor reports. For procurement leaders and enterprise decision-makers, the joint mapping provides a concrete tool to compare vendor threat intelligence more directly when evaluating products and services. For vendors, the mapping project is a midway course — not an effort to impose a single system but a collaborative attempt to make the existing systems easier to translate between.
The concrete detail in Google’s rollout is modest but specific: several dozen core groups will be renamed first; legacy names will remain discoverable; mappings to MITRE ATT&CK and to other vendors’ systems will accompany the change; and an UNC tag will persist until attribution is demonstrably clear. Those steps spell out how Google intends to balance clarity, continuity and the reality that attribution can change.
The result is a familiar paradox: an effort framed as simplifying a problem has added another naming convention to a crowded field — but one designed from the outset to be interoperable with other systems. Whether the addition of Google’s word-pair taxonomy, and the cross-vendor mapping work already under way, will make life easier for defenders in practice is the question the industry now faces as the new names enter routine use.




