Aggregator
AI治理法规与合规
Updated Cyber Threat Actor Naming System
Update (July 30): A table listing the new names of select prominent threat actors was appended to this post.
IntroductionToday, Google Threat Intelligence Group (GTIG) will begin rolling out a unified naming schema for tracking threat actors. This new naming taxonomy represents an effort to standardize tracking across platforms and public reporting.
Why are we Adopting a Different Naming System?Historically, Mandiant and Google’s Threat Analysis Group (TAG) maintained distinct tracking systems, relying on parallel naming schemas that grew independently over time. The creation of GTIG has necessitated a new, fused tracking system, and a new naming system. Thinking to the future, GTIG’s new system will rely on cryptonyms. Relying on sequential numbers or disparate identifiers (e.g. APT1) fails to provide defenders the critical context needed to operate quickly. Threat tracking shouldn’t be an exercise in memorization, but rather one of intuition. The new naming convention aligns with industry standard threat actor naming systems.
Our New SchemaOur new schema utilizes a cryptonym-based approach, employing memorable two-word combinations for each distinct threat actor:
-
The first word is a unique and memorable term chosen to represent the specific actor, particularly names that may have been used in prior public reporting. If no previously used term exists, this word is randomly generated to remove bias, then vetted by our analysts.
-
The second word categorizes threat clusters by motivation, attribution, or activity type based on which category we consider to be most important for defense and response strategies.
The table below provides a sample of how threat actor categories will map to the second word in each cryptonym:
Origin or Type
Group Name
People’s Republic of China
CASTLE
Iran
ION
North Korea
NEPTUNE
Russia
RELIC
Cybercriminal
COMET
Table 1: Examples of Google’s new threat actor naming system categories
We know there are many threat actor tracking schemas in the industry, so we are intentionally seeking to keep this system as simple as possible to streamline operations and facilitate mapping to other naming taxonomies. However, a significant caveat remains: because no two organizations have the exact same visibility into the threat landscape, direct, apples-to-apples comparisons between threat actors are rarely possible. Transitioning to a convention that is simpler to follow and remember is a practical step toward managing a highly intricate tracking problem.
A Work in ProgressWe have initially prioritized renaming several dozen of the most active groups, and will continue this process on a rolling basis. Previous names will remain indexed and searchable in the Google Threat Intelligence (GTI) platform, with MITRE ATT&CK mappings and other vendor aliases preserved, see Figure 1.
Figure 1: Threat actor name appearance in GTI platform on initial rollout
We will continue to use UNC, or “uncategorized” designations for threat clusters that are still in the early stages of investigation, as described here.
Selection of Re-Named Threat ActorsOrigin or Type
Previously Used Names
New Names
Cybercriminal
FIN11
RAZOR COMET
Cybercriminal
FIN6
SQUID COMET
Cybercriminal
FIN7
WILD COMET
Cybercriminal
FIN8
PUNCH COMET
Iran
APT33
BLEAK ION
Iran
APT34
SOLAR ION
Iran
APT35
RICH ION
Iran
APT39
CINDER ION
Iran
APT42, CALANQUE
CALANQUE ION
Iran
TEMP.Zagros, MUDDYCOAST
MUDDY ION
North Korea
APT37
PLAIN NEPTUNE
North Korea
APT45
GRASS NEPTUNE
North Korea
UNC1069, MASAN
MIDNIGHT NEPTUNE
North Korea
Temp.Hermit
HERMIT NEPTUNE
People’s Republic of China (PRC)
APT15
RIVER CASTLE
PRC
APT20
RIDGE CASTLE
PRC
UNC1088
RAVINE CASTLE
PRC
APT27
SHORE CASTLE
PRC
APT30
ISTHMUS CASTLE
PRC
APT31
TIDE CASTLE
PRC
APT40
ISLAND CASTLE
PRC
APT41
SPIRE CASTLE
PRC
APT5
BASALT CASTLE
PRC
Tonto Team
LONE CASTLE
PRC
TEMP.Tick
TICK CASTLE
PRC
UNC2814
DARK CASTLE
PRC
Naikon Team
NAIKON CASTLE
PRC
Conference Crew
CONFERENCE CASTLE
PRC
TEMP.Hex
BASIN CASTLE
PRC
TEMP.Overboard
CAVERN CASTLE
Russia
APT28, FROZENLAKE
LAKE RELIC
Russia
APT29, ICECAP
ICE RELIC
Russia
APT44, FROZENBARENTS
SANDWORM RELIC
Russia
UNC4057, COLDRIVER
COLD RELIC
Russia
TEMP.Vermin
VERMIN RELIC
Russia
Turla Team
TURLA RELIC
Table 2: Selection of Re-named Threat Actors
Microsoft Edge security advisory (AV26-740)
Заплати цент — получи миллион. Лазейка в мосту Verus Ethereum подарила хакеру $7,5 млн
能实时改变的剧情、会行动的 AI 角色,Vivix 灵动时刻正式发布首个实时互动模型
Foxit PDF Reader Flaw Lets Local Attackers Gain SYSTEM Privileges via DLL Sideloading
A recently disclosed vulnerability in Foxit PDF Reader may allow a local attacker with existing code execution to elevate their privileges to NT AUTHORITY\SYSTEM. This issue, tracked as CVE-2026-57239, affects Foxit PDF Reader installations prior to version 2026.2 and arises from the insecure handling of an updater workflow triggered by a user-writable file in the […]
The post Foxit PDF Reader Flaw Lets Local Attackers Gain SYSTEM Privileges via DLL Sideloading appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
Cl0p Hackers Exploit Windchill Servers to Steal Companies’ Secret Product Designs
Cl0p ransomware affiliates are exploiting exposed PTC Windchill and FlexPLM servers to steal engineering and product-design data. The campaign combines software flaws to gain access without credentials, install hidden server-side access, and remove sensitive files before demanding payment. The activity places manufacturers, automotive firms, aerospace organizations, and retail apparel companies at particular risk because Windchill […]
The post Cl0p Hackers Exploit Windchill Servers to Steal Companies’ Secret Product Designs appeared first on Cyber Security News.
Cl0p Targets Internet-Exposed Windchill Servers in Global Engineering Data-Theft Campaign
Cl0p ransomware affiliates are actively exploiting internet-exposed PTC Windchill and FlexPLM deployments in a global data-theft campaign targeting high-value engineering environments. Observed post-exploitation activity includes filesystem enumeration via files such as “flst.txt,” followed by staging and exfiltration of sensitive engineering and product design data. This chaining enables unauthenticated remote code execution, allowing attackers to deploy […]
The post Cl0p Targets Internet-Exposed Windchill Servers in Global Engineering Data-Theft Campaign appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
Исследование Google: ИИ пока не отберёт нашу работу. Он отберёт будущее у тех, кто не успел его освоить
Meta tackles AI-generated accounts with a free Facebook verification badge
Meta has introduced Facebook Verified, a free badge meant to show that a person behind a profile has completed identity verification through a selfie check. (Source: Meta) The company says the goal is to give users a signal that they are dealing with a person, not a bot or an AI-generated account, when browsing Marketplace listings, dating profiles, or Group conversations. “As AI makes it easier to do more on Facebook, a clear signal that … More →
The post Meta tackles AI-generated accounts with a free Facebook verification badge appeared first on Help Net Security.
The Good, the Bad and the Ugly in Cybersecurity – Week 30
Vatican's Official Prayer App Leaks 700K+ Global Users' PII
Illinois Man Pleads Guilty to Phishing 4,500 Snapchat Users to Steal Private Photos
An Illinois man has pleaded guilty to a phishing and account-compromise scheme that targeted thousands of Snapchat users, leading to the theft of private images from numerous women. Federal prosecutors stated that Kyle Svara, 27, of Oswego, Illinois, admitted to charges including aggravated identity theft, wire fraud, computer fraud, conspiracy to commit computer fraud, and […]
The post Illinois Man Pleads Guilty to Phishing 4,500 Snapchat Users to Steal Private Photos appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.