- Google Threat Intelligence Group is replacing its legacy Mandiant and TAG identifiers with two-word cryptonyms, starting with several dozen of its most tracked groups.
- The second word encodes attribution or motive, with CASTLE for China, ION for Iran, NEPTUNE for North Korea, RELIC for Russia, and COMET for criminal outfits that are not visibly linked to a particular country.
- The scheme standardizes names within Google, but adds another convention to an industry that agreed to shared alias mapping just last year.
The Russian military intelligence outfit that most of the security industry knows as Sandworm has chosen another name: Sandworm Relic, at least when Google speaks.
Google Threat Intelligence Group has announced plans to retire the thicket of identifiers it inherited from two separate teams and replace them with two-word cryptonyms, starting with several dozen of the groups it tracks most closely and continuing on an ongoing basis.
Google has recently argued against its longstanding approach of using sequential identifiers like APT1, arguing that a number tells the defender nothing about who they are dealing with. It has begun replacing them with a scheme that it says is more intuitive and makes it easier to determine where an attack is coming from and what motivates it.
Latest videos ofTechnologyRadar
Rationalizing Google’s need to change an already established order
The mechanics are quite simple. Each actor followed receives a couple of words. The first is intended to be distinctive and memorable, and although the security community has already chosen a nickname, Google says it will stick with it. When no such term exists, the word is randomly generated to eliminate bias and then verified by analysts before it comes into use.
The second word categorizes, classifies groups by motivation, attribution or type of activity. The sample table published by Google assigns CASTLE to groups linked to the People’s Republic of China, ION to Iran, NEPTUNE to North Korea, RELIC to Russia, and COMET to financially motivated criminals.
The approach, as CyberScoop notes, echoes CrowdStrike’s long-standing practice of combining a single term with an animal related to the country or motif: PANDA for China, BEAR for Russia, SPIDER for criminals, JACKAL for hacktivists. Google simply changed the animals to words like CASTLE and NEPTUNE.
The move is the latest step after Google announced its $5.4 billion acquisition of Mandiant in 2022, which it eventually combined with its internal threat analysis group to form GTIG.
The merger united two tracking systems that had evolved independently for years, meaning the same activity could appear under two different Google labels depending on the team that wrote the report.
For now, the Russia-linked Sandworm Relic is the only new name that has emerged publicly, and Google isn’t the first to try it.
Microsoft has decided on the climate and countries like China have publicly questioned the powers behind those labels. Google’s decision to “simplify” threat names could still simplify things if it catches on in the rest of the world.
Alternatively, it could simply increase confusion in an industry where there are no fully agreed standards yet. Google and Mandiant joined a Microsoft and CrowdStrike alias mapping effort in June 2025, and The Registry reported that sources at the time indicated that both were interested in adopting the Microsoft-led scheme. Last week’s announcement makes no mention of this. As good as Google’s intentions are, advocates still have one more system to learn.
Follow TechRadar on Google News and add us as a preferred source to receive news, reviews and opinions from our experts in your feeds.




