Google Updates Hacker Group Naming System to Clarify Cyber Threat Tracking | Ukraine news | #hacking | #cybersecurity | #infosec | #comptia | #pentest | #hacker


Behind every memorable hacker label is a larger problem: researchers now track thousands of threat clusters across an increasingly crowded digital battlefield.

For more than a decade, the cybersecurity industry has assigned names to various hacking groups. Some of them, such as Fancy Bear, have entered the public arena through high-profile breaches and memorable names. Others remain known primarily within professional cybersecurity circles.

Often, even experts cannot keep track of everything: each company names groups differently, leading to separate trusted sources that work together to explain who is who – for cybersecurity professionals, government agencies, policymakers, journalists, and the general public.

Last month, Google updated its own system for identifying hacking groups. The old APT1, APT41, and similar designations were part of an approach introduced by Mandiant, which is now part of Google. The new system remains relatively simple: the first part of the name is meant to be memorable and random, while the second indicates the country of origin – Castle for China, Ion for Iran, Neptune for North Korea, and Relic for Russia.

How the new hacker group coding system works

According to Shane Huntley, Google Threat Intelligence Group’s chief technology officer, rethinking the system was a necessary step toward bringing clarity to researchers both inside and outside the company.

we did not expect there to be so many threat groups today

– Shane Huntley

According to John Hultquist, chief analyst at the Google Threat Intelligence Group, Google currently tracks more than 5,000 active clusters across several countries. Huntley added that there is virtually no developed country without its own cyber capabilities and threat groups.

The main benefit of such a system lies not only in theoretical analysis but also in developing a basic understanding of who is attacking, whom they are targeting, and how they operate – so organizations can recognize threats more quickly, prepare for them, neutralize incidents, or investigate them more efficiently.

If you have actually been breached or are dealing with an incident, knowing the behavior of that actor and what they have done before becomes extremely important for responding and addressing the relevant risks

– Shane Huntley

Relying on behavioral data helps organizations respond to crises and provides a starting point for defending against this type of threat. At the same time, monitoring state-sponsored hackers generally presents fewer challenges than tracking cybercriminal groups or groups-for-hire, because the former have more stable targets and activity, while the latter may change, disband, or operate in a more fluid manner.

No one has perfect visibility

– Shane Huntley

By combining the former naming systems used by Google’s Threat Analysis Group and Mandiant, the company created a unified style that reduces the number of schemes researchers need to remember. For everything else, they must rely on available data and public resources.

In light of current trends, Google’s new coding system is designed to make understanding threats faster and more consistent, providing a foundation for quicker responses and more effective action against cyberattacks in the future.





Click Here For The Original Source.

——————————————————–

..........

.

.

National Cyber Security

FREE
VIEW