Google has a new way of talking about the latest cyber threats, so get ready for a lot of crazy new names.



  • Google Threat Intelligence Group is replacing its legacy Mandiant and TAG identifiers with two-word cryptonyms, starting with several dozen of its most tracked groups.
  • The second word encodes attribution or motive, with CASTLE for China, ION for Iran, NEPTUNE for North Korea, RELIC for Russia, and COMET for criminal outfits that are not visibly linked to a particular country.
  • The scheme standardizes names within Google, but adds another convention to an industry that agreed to shared alias mapping just last year.

The Russian military intelligence outfit that most of the security industry knows as Sandworm has chosen another name: Sandworm Relic, at least when Google speaks.

Google Threat Intelligence Group has announced plans to retire the thicket of identifiers it inherited from two separate teams and replace them with two-word cryptonyms, starting with several dozen of the groups it tracks most closely and continuing on an ongoing basis.

Leave a Comment

Your email address will not be published. Required fields are marked *