Google Conducts Dictionary Attack on Security Researchers’ Memory
4 Articles
4 Articles
Google conducts dictionary attack on security researchers’ memory
Google is creating a new naming scheme for the bad actors behind cybersecurity threats, hoping that it will help to standardize the way that attacks are reported. Spoiler: It won’t. Security researchers use these naming schemes so that they can attribute attacks without necessarily knowing exactly who is behind them. Google had naming schemes in use internally: one developed by its own Threat Analysis Group (TAG), and one developed by Mandiant, …
Google has a new way of talking about the latest cyber threats — so get ready for a whole load of crazy new names
Google Threat Intelligence Group is replacing its inherited Mandiant and TAG identifiers with two-word cryptonyms, starting with several dozen of its most-tracked groupsThe second word encodes attribution or motive, with CASTLE for China, ION for Iran, NEPTUNE for North Korea, RELIC for Russia, and COMET for criminal crews not visibly tied to a particular countryThe scheme standardizes naming inside Google but adds another convention to an indus…
Google creates another set of names for threat actors
The new method of naming will involve a two-word approach: The first word will refer to motivation, attribution, or activity type, while the second word will represent the specific threat actor, for example, threats from China will end with “CASTLE,” while those from Russia will end with “RELIC.” If a threat group is not believed to be state-sponsored, then the last word will be “COMET.” Google has already created new names for existing threat …
Coverage Details
Bias Distribution
- 100% of the sources are Center
Factuality
To view factuality data please Upgrade to Premium

