Google's Top Hacker Hunter Explains Why Hacking Groups Get Codenames

aptcodenamescybercriminal groupscybersecuritygoogle threat intelligencehacking groupsstate-sponsored hackersthreat intelligence
For over a decade, the cybersecurity industry has assigned codenames to hacking groups, some of which—like Fancy Bear—have entered mainstream culture due to their high-profile attacks and memorable monikers. Others remain known only within the industry. Often, even insiders struggle to track them all. This is partly because every company uses its own naming system. Resources like MITRE ATT&CK aim to bridge that gap by providing a centralized directory where cybersecurity professionals, government officials, policymakers, journalists, and the public can make sense of the landscape. Last month, Google became the latest company to overhaul its naming system for hacking groups. Gone are the days of APT1, APT41, or APT-whatever-number—a convention popularized by Mandiant, the independent security firm now part of Google. Mandiant was among the first to adopt such a scheme. Under Google's new system, each hacking group receives a memorable, random first name and a second word whose initial denotes the country of origin—for instance, Castle for China, Ion for Iran, Neptune for North Korea, and Relic for Russia. Shane Huntley, CTO of Google Threat Intelligence Group, the company's in-house hacker-hunting team, explained that the change was driven by the need for clarity among security researchers, both internally and externally. In the early 2010s, when companies began publishing cyberattack reports and naming the perpetrators, Huntley told TechCrunch, "we were not expecting to have as many threat groups as we do today." Indeed, tracking has become harder. Google now monitors more than 5,000 'activity clusters' across several countries, according to John Hultquist, chief analyst at Google Threat Intelligence Group. Huntley noted that very few developed nations lack their own cyber capabilities or sophisticated hacking groups. But why name these groups at all? It's not merely an academic exercise, Huntley emphasized. The goal is to establish a baseline understanding of who is attacking whom and how. This enables organizations to recognize threats faster, prepare countermeasures, ideally prevent attacks, or at least investigate incidents more swiftly. All of this, he said, is only possible if hackers are named and tracked consistently. "If you actually get hacked by them, or you're dealing with some incident, knowing how that actor behaves, what they do, what they've done in the past—all of these details become critically important to help the response and also work out your coverage against these threats," said Huntley. For instance, understanding the behavior, goals, and affiliations of the North Korean state-backed Lazarus Group gives defenders a clear starting point for counteraction. While tracking state-sponsored hackers is challenging, it is easier than monitoring cybercriminal gangsand hackers-for-hire, Huntley explained. State-linked groups tend to have predictable structures and motivations, whereas criminal networks are often decentralized and more opportunistic—adding another layer of complexity to the already difficult task of attribution.

via TechCrunch

Related