Key Takeaways
- Google's new naming scheme replaces cryptic APT numbers with memorable first names paired with country-signaling surnames — Castle for China, Ion for Iran, Neptune for North Korea, Relic for Russia.
- The company now tracks over 5,000 "activity clusters," a figure that exposes how wildly the threat landscape has outgrown the taxonomy built for it.
- Shane Huntley argues naming isn't academic theater; it's operational infrastructure that lets defenders predict behavior, accelerate response, and measure coverage gaps.
- The industry still lacks a universal standard, meaning every vendor speaks its own dialect — and defenders pay the translation tax.
Google just killed the APT numbering system. Good. For years Mandiant's APT1, APT41, APT-whatever numbers passed as intelligence. They were not intelligence. They were inventory codes masquerading as insight. The new scheme — memorable first name, country-keyed second name — is not perfect. But it admits what the old system denied: that human analysts need handles they can hold, not identifiers they have to decode.
Shane Huntley, CTO of Google Threat Intelligence Group, makes no bones about why the change came. The taxonomy collapsed under its own weight. Google tracks more than 5,000 "activity clusters" across multiple countries. Huntley puts it dryly: very few developed nations lack their own cyber capabilities and hacking groups. That is the story. Not the naming convention. The explosion.
Every vendor still invents its own nomenclature. CrowdStrike calls them Bears and Pandas. Microsoft uses weather systems. Mandiant used numbers. Google now uses Castle and Ion and Neptune and Relic. The result is a tower of Babel that slows every defender who must translate between them. A universal standard does not exist because no vendor wants to cede branding ground. The cost falls on the incident responder who wastes hours mapping Fancy Bear to APT28 to whatever Google calls them today.
Huntley frames naming as operational infrastructure. He is right. When an intrusion hits, the first question is not "what malware?" but "who?" Knowing the actor's history — their goals, their tradecraft, their sponsors — cuts the investigation from days to hours. The Lazarus Group example Huntley cites proves the point. North Korean operators behave differently than Iranian ones. Different targets. Different persistence. Different tolerance for noise. That distinction is not academic. It dictates which logs you pull first, which credentials you rotate, which executives you wake at 3 a.m.
State-sponsored groups are the easy ones. They leave signatures. They follow doctrine. They answer to bureaucracies that hate embarrassment. Cybercrime crews are harder. They mutate. They franchise. They sell access to each other. They operate like markets, not militaries. Huntley's interview cuts off before that distinction gets its due. That omission matters. The naming system works best where attribution is cleanest. It frays where the threat is messiest.
The industry treats naming as a solved problem. It is not. It treats 5,000 clusters as a metric of maturity. It is a metric of failure. Every new cluster is a gap in prior visibility. The naming convention Google unveiled last month is a better filing cabinet. But the room is still burning.