HomeIntelligenceBrief
BREACH BRIEF⚪ Informational ThreatIntel

Google Introduces New Weather‑Based Threat Actor Taxonomy (Castle, Ion, Neptune, Relic, Comet)

Google unveiled a weather‑themed naming system for state‑sponsored and criminal groups to streamline threat‑intel mapping. The change impacts SOC 2 vendor‑risk programs that rely on consistent third‑party threat data.

LiveThreat™ Intelligence · 📅 July 28, 2026· 📰 databreachtoday.com
Severity
Informational
TI
Type
ThreatIntel
🎯
Confidence
High
🏢
Affected
3 sector(s)
Actions
2 recommended
📰
Source
databreachtoday.com

Google Introduces New Weather‑Based Threat Actor Taxonomy (Castle, Ion, Neptune, Relic, Comet)

What Happened — Google’s threat‑intelligence team announced a new naming system for state‑sponsored and cyber‑crime groups, using weather‑related prefixes (Castle, Ion, Neptune, Relic, Comet) paired with a second word that conveys motivation or origin. The schema replaces a patchwork of legacy identifiers (e.g., APT44, Sandworm) and aims to simplify mapping across industry taxonomies.

Why It Matters for Compliance & Audit Readiness

  • Consistent threat‑actor naming feeds directly into vendor‑risk programs, enabling repeatable, auditable due‑diligence checks on third‑party threat exposure.
  • A unified taxonomy reduces manual reconciliation effort, supporting continuous control monitoring and defensible SOC 2 evidence for the Vendor Management principle.
  • Aligning internal threat feeds with Google’s schema helps maintain an up‑to‑date threat‑intel repository, a key input for risk assessments required by SOC 2 CC6.1 (Third‑Party Risk Management).

Who Is Affected — Enterprises that rely on external threat‑intel feeds, MSSPs, and any organization subject to SOC 2 vendor‑management controls across all sectors.

Recommended Actions

  • Map Google’s new identifiers to your existing threat‑intel taxonomy and update any automated enrichment pipelines.
  • Document the mapping process as part of your vendor‑risk evidence package for SOC 2 audits.
  • Incorporate the refreshed taxonomy into continuous monitoring tools to ensure real‑time alerts remain audit‑ready.

Source: DataBreachToday

Technical Notes

  • No new vulnerability or exploit disclosed; the change is purely nomenclature‑focused.
  • Google’s system pairs a “origin” word (e.g., Castle = China) with a contextual descriptor (e.g., Relic).

Source: same as above

📰 Original Source
https://www.databreachtoday.com/blogs/insane-castle-hurricane-apt-codename-confusion-proliferates-p-4162

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Vendor Risk Hub

This is the scenario continuous vendor monitoring is built to catch.

When a vendor is compromised, your SOC 2 vendor-management controls are what produce the audit trail showing you knew, assessed, and acted. The Verisq AI Trust Operations platform tracks that continuously.

Explore the Verisq AI Trust Operations platform →