A Naming System Built for the Long Game
Google recently overhauled how it identifies and labels hacking groups – and the reasoning behind that decision cuts straight to the core of how the cybersecurity industry tracks adversaries at scale.

The Problem With Naming Threat Actors
When a security team discovers a new hacking operation, the first challenge isn’t stopping it – it’s describing it. Researchers need a way to refer to a group consistently across reports, briefings, and internal databases without accidentally exposing classified intelligence, ongoing investigations, or the identities of human sources embedded near those operations. A real name, a country attribution, or even a geographic reference can carry diplomatic and legal weight that a codename quietly sidesteps.
Codenames solve this by creating a neutral container. The label “APT29” or a weather-themed alias carries no inherent accusation. It can be used in a public blog post, shared with law enforcement, or handed to a journalist without triggering an international incident. The name becomes a handle – stable enough to build a body of research around, vague enough to avoid overcommitting before attribution is certain.
Attribution in cybersecurity is rarely clean. A group operating out of one country might use infrastructure rented in another, tools developed by a third party, and tactics borrowed from criminal forums that span dozens of nationalities. Pinning a human name or a national flag to that activity prematurely can embarrass researchers, mislead defenders, and give adversaries a public signal that they’ve been identified – prompting them to change their methods before the full picture emerges.
Google’s threat intelligence operation, which includes the team formerly known as Mandiant after the company’s 2022 acquisition, sits at the center of this tension daily. The researchers tracking these groups are, by most measures, among the most experienced adversary-hunting teams in the world. When Google decided to revise its naming conventions, it wasn’t a cosmetic change – it reflected years of accumulated friction with the old system and a recognition that the industry’s patchwork of competing labels was creating real confusion for defenders trying to act on threat intelligence.
How Codenames Actually Work in Practice
Different security companies have developed entirely different naming frameworks over the years, and the result is a landscape where the same hacking group might be called four different things depending on which vendor’s report you’re reading. Microsoft uses weather phenomena. CrowdStrike uses animals paired with nation-state associations. Google, following the Mandiant acquisition, inherited a system built around numbers and letters that was functional but increasingly strained as the number of tracked groups grew into the hundreds.

The codename system does more than avoid diplomatic friction – it structures knowledge. When a research team tags a cluster of malicious activity under a single identifier, everything associated with that cluster accumulates: malware samples, command-and-control infrastructure, victimology patterns, timing signatures, and operational security habits. Over months or years, that accumulation becomes a profile detailed enough to predict where a group might strike next, what tools they’re likely to use, and how quickly they adapt after exposure.
That predictive layer is where the real value sits. A defender who knows they’re being targeted by a specific tracked group can look up that group’s historical behavior and make informed decisions about where to focus detection resources. Without a stable identifier tying all of that research together, the intelligence dissolves into a pile of disconnected incidents with no thread connecting them. The codename is, in effect, the index card that holds the file together.
There’s also a communication function that operates almost entirely outside the technical community. When governments, boards of directors, or legal teams need to understand a threat, researchers have to translate extraordinarily complex technical activity into something actionable for non-specialists. A codename gives everyone in that conversation a shared reference point without requiring the audience to understand the underlying forensics. It’s a compression tool as much as an investigative one.
Google’s revised naming approach signals a push toward greater internal consistency – a way to reduce the overhead of cross-referencing their own historical data against a system that had grown organically rather than by design. The specifics of what changed and how the new taxonomy is structured reflect a broader industry conversation about whether competing vendor labels are helping or hindering the collective defense effort. When one company calls a group “Cozy Bear” and another calls them “Midnight Blizzard,” defenders running multi-vendor security stacks have to do extra work just to confirm they’re looking at the same threat.
What This Means for the Broader Security Landscape
The question Google’s naming overhaul quietly raises is whether the industry is ready to move toward any form of standardization. Right now, each major vendor owns its own taxonomy, and those taxonomies are partly marketing assets – distinctive enough to be memorable in analyst reports and conference presentations. Giving that up in favor of a shared identifier system would require a level of coordination that has historically been elusive, even among organizations that cooperate on threat sharing in other ways.

Meanwhile, the hacking groups themselves keep evolving. Some splinter into subgroups with distinct tactics. Others go dark for months, resurface with new tooling, and force researchers to debate whether they’re looking at the same actor or a successor operation. The codename that once cleanly described a group can become ambiguous as the group itself changes – and the decision of whether to retire a label, split it, or extend it carries real consequences for how defenders prioritize their resources. Google’s top threat researchers are navigating exactly that kind of question right now, trying to build a naming system that stays useful as the adversaries it tracks refuse to hold still.








