Google adds to confusion with new names for threat actors
Summary
Google is introducing a new, two-word naming scheme for cyber threat actors, aiming to standardize attribution and reporting. The scheme uses the first word to denote motivation, attribution, or activity type, and the second word to represent the specific actor or region, such as "CASTLE" for China-based threats or "RELIC" for Russia-based threats. Critics suggest Google could have adopted existing naming conventions from Microsoft or industry collaborations instead of creating a new system.
IFF Assessment
This article discusses a new, potentially confusing naming scheme for threat actors introduced by Google, which could complicate attribution efforts for defenders.
Defender Context
Defenders often rely on standardized naming conventions for threat actors to track campaigns and attribute attacks. The introduction of a new, potentially idiosyncratic naming scheme by a major player like Google could create confusion and hinder effective threat intelligence sharing and analysis.