{
  "id": 314859,
  "title": "Google’s top hacker hunter explains why hacking groups get codenames",
  "url": "https://urgent.news/2026/08/08/googles-top-hacker-hunter-explains-why-hacking-groups-get-codenames",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-08-08T15:00:00.000Z",
  "source": {
    "name": "TechCrunch",
    "slug": "techcrunch",
    "url": "https://techcrunch.com/2026/08/08/googles-top-hacker-hunter-explains-why-hacking-groups-get-codenames/"
  },
  "original_language": "en",
  "account": "Over the past decade, the cybersecurity industry has been assigning codenames to various hacking groups. Some, like Fancy Bear, have gained widespread recognition due to their notorious attacks and catchy names. However, many of these groups remain unknown even to those within the cybersecurity community. Insiders often struggle to keep track of the diverse naming conventions used by different companies. To address this issue, Google has recently revamped its naming system for hacking groups, replacing the previous APT1, APT41, or APT numbering scheme used by Mandiant, now part of Google. The new system is straightforward: a unique, easy-to-remember name for the group, followed by a second word indicating the country of origin: Castle for China, Ion for Iran, Neptune for North Korea, and Relic for Russia. Shane Huntley, Google's chief technology officer for Threat Intelligence, explained that this revamp was necessary to provide clarity for security researchers both internally and externally. Currently, Google monitors over 5,000 activity clusters in various countries. Huntley emphasized that naming hacking groups is not merely an academic exercise but a practical necessity. By establishing a baseline understanding of who is attacking whom and how, organizations can more quickly recognize threats, prepare defenses, and investigate incidents more efficiently. This is particularly crucial when dealing with state-sponsored hackers, as their consistent targets and activities make them easier to track compared to cybercriminal groups and hackers-for-hire. Huntley acknowledged that while naming conventions may differ among companies due to their unique data and telemetry, this is an unavoidable challenge. Despite this, the unification of Google's naming system with that of Mandiant simplifies the process, leaving fewer schemes to remember.",
  "summary": "Google recently changed how it refers and assigns names to hacking groups. TechCrunch spoke with one of the world’s foremost experts on tracking hackers to understand why companies give hackers codenames.",
  "key_points": [
    "Google revamps hacking group naming system from APT to Castle, Ion, Neptune, Relic.",
    "New system uses unique names followed by country of origin.",
    "Shane Huntley explains necessity for clarity in threat intelligence."
  ],
  "editors_take": null,
  "illustration": "https://urgent.news/ill/314859.png",
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}