
Google Threat Intelligence Group (GTIG) introduced a unified cryptonym-based naming system for tracking cyber threat actors, standardizing threat attribution across platforms. The change addresses fragmentation between Mandiant and Google’s Threat Analysis Group (TAG), which previously used separate naming systems. The new system assigns each threat actor a memorable two-word cryptonym, with the first word as a unique identifier and the second indicating motivation or attribution. For example, the Russian state-linked group APT44/Sandworm is now called SANDWORM RELIC. This streamlines triage and cross-team communication, though GTIG acknowledges that direct comparisons between naming schemas across vendors remain imprecise.