Google Adopts New Threat Actor Naming System
Google has announced that Google Threat Intelligence Group (GTIG) is adopting a new cryptonym-based naming convention for tracking threat actors.
According to the internet giant, the schema moves away from sequential numbers and disparate identifiers, relying instead on two-word combinations for each activity cluster.
The first word, Google explains, is a unique and memorable term that may have been used in public reporting and which is meant to represent the threat actor. A randomly generated term will be used if none exists.
The second word is meant to place each threat actor into a specific category based on motivation, attribution, or activity type.
As an example, Google will use ‘Castle’ as the second word for threat actors from China, ‘Ion’ for those from Iran, ‘Neptune’ for North Korean groups, ‘Relic’ for Russian threat actors, and ‘Comet’ for cybercrime gangs.
Under the new naming scheme, Russia’s notorious Sandwormgroup, which...
Copyright of this story solely belongs to securityweek.com. To see the full text click HERE