Google Consolidates Threat Actor Naming, Launches Two‑Word Cryptonym System
What Happened — Google Threat Intelligence Group (GTIG) announced a unified naming scheme for the cyber‑threat actors it tracks. The new system replaces legacy APT‑style identifiers with a two‑word cryptonym (e.g., SANDWORM RELIC) that pairs a familiar group name with a category tag indicating attribution or motivation. The change follows the merger of Mandiant and Google’s Threat Analysis Group and will be rolled out across the Google Threat Intelligence platform.
Why It Matters for Compliance & Audit Readiness
- Consistent threat‑actor identifiers simplify mapping external threat intelligence to internal vendor‑risk registers, a core SOC 2 CC6.1 control.
- A stable taxonomy reduces the effort needed to maintain audit evidence of third‑party risk assessments and continuous monitoring.
- Aligning Google’s naming with other industry taxonomies (e.g., MITRE ATT&CK) eases evidence collection for vendor‑management policies and demonstrates due‑diligence to auditors.
Who Is Affected — Cloud‑service providers, SaaS vendors, and enterprises that rely on Google’s threat‑intelligence feeds for vendor‑risk programs, especially those in technology, finance, and regulated industries.
Recommended Actions
- Update your threat‑intelligence ingestion pipelines to map the new two‑word cryptonyms to existing vendor‑risk records.
- Document the taxonomy change in your SOC 2 vendor‑management policy and include it in your continuous‑monitoring evidence set.
- Validate that your risk‑scoring models still correctly attribute threat actor categories after the rename.
Technical Notes — The naming change is a procedural update; no new CVEs or exploit techniques are disclosed. GTIG retains legacy aliases for searchability and continues to map each cryptonym to MITRE ATT&CK techniques. Source: Help Net Security