None
EN
Google Changes How It Names Hacking Groups to Simplify Threat Tracking
[]
News – DMR News
Google has introduced a new naming system for hacking groups as the number of cyber threat actors it tracks continues to grow.
Google acquired Mandiant in 2022 and has now unified the naming systems previously used by Mandiant and Google’s former Threat Analysis Group.
China-linked groups use “Castle,” Iran-linked groups use “Ion,” North Korea-linked groups use “Neptune,” and Russia-linked groups use “Relic.”
Google now tracks more than 5,000 activity clusters across several countries, according to John Hultquist, chief analyst at Google Threat Intelligence Group.
MITRE ATT&CK maintains a directory of tracked threat groups that links many of those aliases and notes where organisations may define the same activity differently.