# Google Gives Threat Actors Better Names — and Quietly Tightens Its Grip on the Threat Intel Market


Sandworm. The name has meant something in security circles for over a decade — a Russian military hacking group responsible for Ukraine's 2015 power grid blackout, NotPetya, and a trail of destructive attacks that reads like a case study in state-sponsored aggression. It's a name that security teams recognize immediately, a name that triggers institutional memory.


Google's Threat Intelligence Group just renamed it Sandworm Relic.


That's not a complaint — it's actually a reasonable system. But the move is worth examining carefully, because it's both a genuine operational improvement and a quiet consolidation of influence over how the security industry talks about its adversaries.


## Fourteen Names for One Hacking Group


To understand why Google is doing this, you need to understand how badly broken the current naming regime is.


Sandworm — the group Google previously tracked as APT44 — is simultaneously known as Blue Echidna, Electrum, FrozenBarents, G0034, Iridium, Iron Viking, Quedagh, Seashell Blizzard, TEMP.Noble, TeleBots, UAC-0082, UAC-0113, and Voodoo Bear. Fourteen names, one group.


Every major threat intelligence vendor developed its own tracking schema internally, named clusters based on their own visibility, and then published reports using their own names. A Mandiant report and a CrowdStrike report about the same Russian GRU unit read like dispatches from parallel universes. Defenders trying to correlate intelligence across vendors have to maintain their own internal Rosetta Stone just to understand who's hitting them.


This isn't a minor inconvenience. It's a genuine operational problem that slows incident response, complicates threat hunting, and forces every security team to do translation work before they can act on intelligence.


## How the New System Works


Google's answer is a two-word cryptonym schema. The first word is a memorable identifier — ideally one already in use in public reporting, or a randomly generated term if nothing has stuck. The second word categorizes the actor by origin or motivation.


The category words are: Castle (China), Ion (Iran), Neptune (North Korea), Relic (Russia), and Comet (cybercrime). So Sandworm becomes Sandworm Relic. A newly discovered Iranian espionage cluster with no prior public name might become something like Obsidian Ion.


The elegance here is that the system preserves institutional memory where it exists — you don't have to unlearn "Sandworm" — while appending a categorical breadcrumb that immediately tells you who you're dealing with. A new analyst seeing "Sandworm Relic" in a report for the first time gets the origin without having to look it up.


Google says previous names remain indexed and searchable in the Google Threat Intelligence platform, with MITRE ATT&CK mappings and vendor aliases preserved. The UNC designation for uncategorized clusters stays intact. This is smart rollout design — they're not blowing up the old taxonomy, they're layering on top of it.


## This Isn't Google's Fight Alone


The naming problem has attracted multiple large-scale attempts at standardization in the past few years, and it's worth placing Google's move in that context.


Microsoft switched to weather-themed names in 2023 — Midnight Blizzard for Cozy Bear, Volt Typhoon for Chinese infrastructure targeting campaigns. The system was logical: weather words for the cluster name, nation-state descriptors (Blizzard for Russia, Typhoon for China, Sandstorm for Iran) as suffixes. It improved internal clarity at Microsoft but created exactly one more naming system for everyone else to track.


CrowdStrike uses animals — Bear for Russia, Panda for China, Kitten for Iran, Spider for cybercrime. Mandiant, before its absorption into Google, used numbered APT designations. The result is an industry that has standardized on not standardizing.


Google explicitly says it's "intentionally seeking to keep this system as simple as possible to streamline operations and facilitate mapping to other naming taxonomies." The word "mapping" is doing a lot of work in that sentence. The goal isn't just internal clarity — it's interoperability, the ability to trace a name in Google's system back to its equivalent in Microsoft's, CrowdStrike's, or Mandiant's.


Whether the rest of the industry adopts Google's schema, continues with their own, or meets somewhere in the middle is the real question. Google has significant pull here: it acquired Mandiant in 2022, absorbing one of the most authoritative threat intelligence brands in the business. GTIG now publishes from a position of genuine credibility. But CrowdStrike and Microsoft aren't going to abandon their naming conventions to align with Google's, and smaller vendors will follow whoever their enterprise customers prefer.


## What This Means for Defenders


For security operations teams, the immediate practical impact is modest. Existing threat feeds don't change overnight, SIEMs will still ingest Mandiant's APT labels, and no one's threat model needs to be rewritten because Sandworm now has "Relic" appended to it.


The longer-term benefit lands in threat intelligence sharing and cross-vendor correlation. If GTIG reports start appearing with names that map cleanly to categories, and if other vendors adopt similar suffixes even informally, the translation overhead shrinks. Junior analysts spend less time answering "who is Electrum?" and more time doing actual triage.


Threat intel platforms that aggregate across vendors — recorded intelligence products, TIPs, SIEM enrichment layers — are the ones best positioned to benefit immediately. They can build the mapping tables once and surface unified names in their UIs without waiting for vendor consensus.


## HackWire Analysis


Google's new naming schema is a genuinely useful operational improvement, but reading it purely as a taxonomic housekeeping exercise misses the strategic dimension.


The threat intelligence market has long been fragmented by design — every vendor's proprietary naming schema is, functionally, a lock-in mechanism. Defenders who build workflows around CrowdStrike's adversary labels, or who train teams using Mandiant's APT numbering, are partially dependent on those vendors to maintain and update that knowledge base. Naming conventions are product features.


By publishing a clean, mappable, two-word schema and explicitly committing to MITRE ATT&CK alignment and cross-vendor alias preservation, Google is positioning GTIG's taxonomy as the interoperability layer the industry lacks. That's a quiet but significant power move. If defenders start normalizing to Google's names — because they appear in the Google Threat Intelligence platform, because they map to Mandiant historical reporting, because they're easy to remember — that increases the stickiness of the entire Google TI ecosystem.


The comparison that comes to mind is DNS. The naming system for the internet was always political as much as technical. Whoever controls the authoritative namespace has structural leverage. Google isn't claiming that authority directly — they've explicitly said they want the system to map to others — but they're offering themselves as the canonical bridge.


The deeper problem this doesn't solve is visibility fragmentation. Google acknowledges this directly: different vendors see different slices of the threat landscape, so a cluster that CrowdStrike has tracked for three years might be a brand-new UNC designation at Google. Better naming doesn't fix uneven telemetry. A Russian cluster that only shows up in Splunk's data or a Chinese actor that Palo Alto Unit 42 identified in OT networks won't automatically benefit from GTIG's cleaner taxonomy.


Defenders should treat this as a useful signal about direction, not a near-term workflow change. Start building internal glossaries that map vendor names to each other now. The teams that do that translation work proactively are the ones who'll benefit fastest when — and if — the industry moves toward convergence.


— HackWire Editorial


## Related Coverage


  • Read more in our [Vulnerabilities](https://www.hackwire.news/category/vulnerabilities) coverage
  • Cross-reference with [Breaches](https://www.hackwire.news/category/breaches) and [Malware](https://www.hackwire.news/category/malware)
  • Stay current via the [HackWire homepage](https://www.hackwire.news/)