Why Google Gives Hacking Groups Codenames According to Its Top Hacker Hunter

TL;DR
- Google has unified its confusing patchwork of threat actor names (from Mandiant's APT numbers and TAG's codenames) into a single, structured system to end the industry-wide confusion where one hacking group has five different names.
- The new convention uses clear prefixes and descriptors to instantly identify a group's origin and motivation — distinguishing state-sponsored actors tied to Russia, China, Iran, and North Korea from financially-motivated criminal groups.
- According to Google's top hacker hunter, consistent and transparent attribution isn't about giving hackers cool nicknames — it's critical for helping defenders quickly understand who is attacking them, what they want, and how to stop them.
The Secret Language of Cyberwar
If you follow cybersecurity news, you've seen the names: Fancy Bear, Cozy Bear, Volt Typhoon, Charming Kitten, APT28, APT29, UNC2452. It sounds like a zoo mixed with a weather forecast, and for years, that's been part of the problem.
For anyone trying to defend a network, one Russian hacking group might be called Fancy Bear by CrowdStrike, APT28 by Mandiant, Forest Blizzard by Microsoft, and Pawn Storm by Trend Micro. They are all the same group — the one behind the DNC hack in 2016 and countless attacks since — but you wouldn't know it from the names. This fragmented naming system has made it incredibly difficult for security teams to share intelligence and know who they are actually fighting.
That is exactly why Google decided to revamp its entire system.
Why Hackers Get Codenames in the First Place
Tracking hackers isn't like tracking conventional criminals. Nation-state and criminal groups operate in the shadows, constantly changing their malware, infrastructure, and techniques. Security researchers need a way to cluster related activity together over months and years, even when they don't know the real identities of the people behind the keyboard.
That cluster needs a name. A codename becomes a placeholder for a dossier: the group's typical targets, its favorite malware, its working hours, its skill level, and its likely sponsor.
Without codenames, every new phishing email or piece of malware would look like an isolated incident. With them, defenders can connect the dots and say, "This isn't a random attack, this is consistent with a Russian intelligence group that targets governments and think tanks." That context changes how you respond.
Inside Google's New Naming Playbook
Earlier this year, Google's Threat Intelligence Group (GTIG) — which now combines the former Mandiant and Google's Threat Analysis Group (TAG) — announced it was overhauling its naming convention to make that context instant and intuitive.
The old system was a legacy of two different teams. Mandiant used sequential numbers like APT44 for state-sponsored groups and FIN for financially motivated ones, while TAG used its own codenames. The new unified system is designed to be more transparent at a glance.
Here's how it works:
For state-sponsored actors, the name now clearly indicates the suspected sponsoring country. Groups linked to Russia, China, Iran, North Korea, and others are given distinct, themed name families. This mirrors the approach Microsoft took with its weather-themed names (Blizzard for Russia, Typhoon for China, Sandstorm for Iran), but Google's system is built to be more descriptive and scalable.
For criminal and financially motivated actors, Google uses a different set of designators to clearly separate espionage from crime. This helps defenders immediately understand the actor's motivation: are they trying to steal secrets for a government, or steal money for themselves?
Crucially, Google is retaining its UNC (Uncategorized) designation — like UNC3886 or UNC4841 — for newly discovered clusters of activity that haven't yet been formally attributed or merged into a named group. Once researchers have enough confidence in the patterns, a UNC group can be promoted to a full named actor. This prevents premature or inaccurate attribution.
The goal, according to Google, is one name, one actor, with no confusion about who does what and for whom.
What Google's Top Hacker Hunter Says About Attribution
John Hultquist, Chief Analyst at Google's Threat Intelligence Group and one of the industry's most well-known hacker hunters, has been the public face explaining the shift. He argues the change isn't just cosmetic — it's operational.
Hultquist has long warned about the "attribution fog" that helps attackers. When a hospital, a utility, or a government agency gets hit, the first question is not just how it happened, but who did it and why. A name tied to a clear country and motivation tells a defender what to expect next.
A Russian SVR-linked group like the one behind the SolarWinds supply chain attack will be stealthy, patient, and focused on long-term espionage. A Chinese group might be focused on stealing intellectual property at scale. An Iranian group might be more destructive and retaliatory. A North Korean group is likely after funds to evade sanctions.
If you confuse one for the other because the names are a mess, you will defend against the wrong playbook. Hultquist's point is that clear, consistent naming turns raw technical data into actionable intelligence. It allows a security analyst at a small company to benefit from the same context that Google sees when tracking nation-states.
He also emphasizes that good attribution is disciplined attribution. Not every attack can or should be immediately tied to a country. The UNC system is intentionally cautious, giving researchers space to track activity without making a political claim they can't back up with evidence.
Why a Name Is More Than Just a Name
For Google, which protects billions of users across Gmail, Chrome, and Google Cloud, naming is a defensive weapon. Standardizing names makes automated defenses better, threat reports easier to read, and collaboration with governments and other security firms faster.
It also matters for the public. When Google warns that a group linked to Iran is targeting journalists or that a Chinese group is exploiting a new zero-day vulnerability, a clear and consistent name helps policymakers, journalists, and the public understand the scale and source of the threat without needing a decoder ring.
In the end, the codenames aren't meant to glorify hackers. They are meant to demystify them. By giving a faceless cluster of hackers a consistent name and a clear origin story, Google is trying to make an invisible war a little more visible — and a lot easier to defend against.
Get All The Latest Updates Delivered Straight To Your Inbox For Free!