Google just rewrote the rulebook on how the cybersecurity industry tracks nation-state hackers. The company’s Mandiant threat intelligence unit – acquired for $5.4 billion in 2022 – quietly rolled out a new naming convention for Advanced Persistent Threat groups, and the reasoning reveals how messy tracking cyber warfare has become. In an exclusive interview with TechCrunch, Google’s top hacker hunter broke down why giving attackers memorable codenames isn’t just about branding – it’s about survival in an industry drowning in conflicting intelligence.
Google is tackling one of cybersecurity’s messiest problems – the fact that every vendor calls the same hacking group by a different name. The company’s Mandiant division, which Google acquired in a $5.4 billion deal that closed in 2022, just overhauled how it assigns codenames to state-sponsored hacking groups.
The timing isn’t coincidental. As AI-generated phishing attacks and automated reconnaissance tools blur the lines between different threat actors, the industry’s fragmented naming conventions have become a liability. When Microsoft calls a group “Nobelium” while CrowdStrike dubs them “Cozy Bear” and Mandiant tracks them as “APT29,” security teams waste precious hours just figuring out who they’re fighting.
Mandiant essentially invented this naming game. The firm pioneered the APT designation – Advanced Persistent Threat – that became shorthand for state-sponsored hacking groups. Their numbering system (APT1, APT28, APT29) gave the cybersecurity world a common language, even as competitors developed their own animal-themed and mythology-based alternatives.
But that standardization broke down as the threat landscape exploded. According to Google’s Cloud Security Report, the company now tracks over 300 distinct threat groups – a number that’s tripled since 2020. Each vendor maintains its own taxonomy, creating a Tower of Babel situation when teams try to share intelligence across platforms.
The new Mandiant system aims to cut through this confusion, though Google hasn’t publicly detailed all the changes. What’s clear is that the company is leveraging its unique position – Mandiant’s historical credibility plus Google’s AI capabilities – to push the industry toward better coordination.
This matters because modern cyberattacks move too fast for manual correlation. When a security operations center sees an alert, they need to instantly know if it matches patterns from a known group. If analysts have to cross-reference five different naming schemes, attackers gain hours or days of dwell time.
The challenge goes deeper than nomenclature. Hacking groups morph constantly – they split, merge, change tactics, and deliberately mimic each other’s techniques. Mandiant tracks what it calls “clusters” of activity that might represent the same actor using different infrastructure. Assigning a definitive name requires high confidence in attribution, something that’s increasingly difficult when groups use off-the-shelf malware and rented botnets.
Google’s also dealing with a credibility tightrope. The company needs Mandiant’s threat intelligence to sell its Google Cloud security services, but it can’t be seen as crying wolf with overblown threat assessments. The naming convention serves as a quality control mechanism – only groups meeting certain thresholds of sophistication and persistence get official designations.
The industry will be watching whether competitors follow Google’s lead. Microsoft recently revamped its own naming system, moving to a weather-themed taxonomy, while CrowdStrike sticks with animals. Each vendor has incentives to maintain its own brand, but the lack of interoperability hurts everyone when threat intelligence can’t flow freely between platforms.
For enterprise security teams, this arcane naming debate has real consequences. Boards want to know if their company is being targeted by “that Russian group from the news,” but translating media reports into actionable intelligence requires knowing all the aliases. Google’s push for standardization could mean fewer missed connections – or it could just add another naming scheme to the pile.
Google’s naming overhaul is really a proxy battle for who controls the cybersecurity industry’s shared language. As nation-state attacks accelerate and AI makes attribution harder, the vendor that sets the standard for tracking threats gains enormous influence. Mandiant built that credibility over decades, but maintaining it requires adapting to a threat landscape that’s unrecognizable from even five years ago. Whether the rest of the industry adopts Google’s new system or fragments further will determine if we’re moving toward better threat intelligence sharing or just adding more confusion to an already chaotic field.
Click Here For The Original Source.
