Original briefings. Zero spin.
Every story is an original briefing written from 60+ sources across the spectrum — sources linked so you can verify it yourself.
Google Overhauls Its Hacker-Naming System: 5,000 Groups, One New Code

Google quietly changed how it labels the world's hackers last month. Out with APT1, APT41, and the rest of Mandiant's old alphanumeric system. In with a new naming scheme built for clarity, according to Shane Huntley, chief technology officer of Google Threat Intelligence Group.
Every hacking group gets a first name that's random and memorable. The second word starts with a letter that flags the country behind the group. Castle means China. Ion means Iran. Neptune means North Korea. Relic means Russia.
Mandiant, the cybersecurity firm Google now owns, was the first to build a naming system for hacking groups back in the early 2010s. Huntley told TechCrunch that nobody expected the problem to get this big. "We were not expecting to have as many threat groups as we do today," he said.
They underestimated it badly. Google now tracks more than 5,000 separate hacking activity clusters across multiple countries, according to John Hultquist, chief analyst at Google Threat Intelligence Group. Huntley said there are very few developed nations left that don't run their own offensive cyber operations.
Why bother naming them at all
Huntley said this isn't an academic exercise. The point is giving defenders a baseline: who's attacking, how they operate, what they're after. If a company gets hit and knows it's dealing with, say, North Korea's Lazarus Group, that history tells responders what the hackers typically want, who they answer to, and how they usually move.
A ransomware crew shaking down a hospital for cash behaves nothing like a nation-state team stealing defense contractor blueprints. Knowing which one you're facing changes everything about the response, from who you call to how fast you need to move.
The old system's biggest problem was fragmentation. Every cybersecurity company invented its own labels for the same groups. Microsoft, CrowdStrike, Mandiant, and others all had different code names for identical hacking crews, which meant researchers, journalists, and government officials were constantly translating between naming systems just to confirm they were talking about the same threat.
That's part of why cross-industry tracking resources exist now, aiming to give researchers, policymakers, and the public a single reference point for who's who in the world of state-linked hacking.
The bigger picture Google's numbers reveal
Cyber intrusion has become a normalized tool of statecraft, not a rare event. China, Russia, Iran, and North Korea get the most attention because their operations are the most aggressive and the best documented. But Huntley's comment that almost every developed nation now runs cyber capabilities suggests the field is far broader than the usual suspects.
Google's rebrand happened last month, and the scale of state-sponsored hacking has been documented for years by Mandiant, Microsoft, and government agencies like CISA. What's changed is the packaging: a naming system built to survive an era where a handful of named groups has ballooned into thousands of tracked clusters.
The unresolved question is whether unified naming will actually change outcomes. Naming a threat doesn't stop it. China's Castle-tagged groups, Russia's Relic-tagged groups, Iran's Ion-tagged groups, and North Korea's Neptune-tagged groups will keep operating whether cybersecurity firms agree on what to call them or not. The real test comes the next time a major breach hits a U.S. company or government agency, and whether Google's new labels actually get adopted industry-wide or just add one more naming convention to an already crowded field.
Sources used for this briefing
This briefing was written by UBH's AI agent — these are the reporting inputs it draws on, linked so you can verify.