Home › Intelligence › Brief
BREACH BRIEF⚪ Informational ThreatIntel

Google Introduces New Weather‑Based Threat Actor Taxonomy (Castle, Ion, Neptune, Relic, Comet)

Google unveiled a weather‑themed naming system for state‑sponsored and criminal groups to streamline threat‑intel mapping. The change impacts SOC 2 vendor‑risk programs that rely on consistent third‑party threat data.

LiveThreat™ Intelligence · 📅 July 28, 2026· 📰 databreachtoday.com
⚪
Severity
Informational
TI
Type
ThreatIntel
🎯
Confidence
High
🏢
Affected
3 sector(s)
✅
Actions
2 recommended
📰
Source
databreachtoday.com

Google Introduces New Weather‑Based Threat Actor Taxonomy (Castle, Ion, Neptune, Relic, Comet)

What Happened — Google’s threat‑intelligence team announced a new naming system for state‑sponsored and cyber‑crime groups, using weather‑related prefixes (Castle, Ion, Neptune, Relic, Comet) paired with a second word that conveys motivation or origin. The schema replaces a patchwork of legacy identifiers (e.g., APT44, Sandworm) and aims to simplify mapping across industry taxonomies.

Why It Matters for Compliance & Audit Readiness

  • Consistent threat‑actor naming feeds directly into vendor‑risk programs, enabling repeatable, auditable due‑diligence checks on third‑party threat exposure.
  • A unified taxonomy reduces manual reconciliation effort, supporting continuous control monitoring and defensible SOC 2 evidence for the Vendor Management principle.
  • Aligning internal threat feeds with Google’s schema helps maintain an up‑to‑date threat‑intel repository, a key input for risk assessments required by SOC 2 CC6.1 (Third‑Party Risk Management).

Who Is Affected — Enterprises that rely on external threat‑intel feeds, MSSPs, and any organization subject to SOC 2 vendor‑management controls across all sectors.

Recommended Actions

  • Map Google’s new identifiers to your existing threat‑intel taxonomy and update any automated enrichment pipelines.
  • Document the mapping process as part of your vendor‑risk evidence package for SOC 2 audits.
  • Incorporate the refreshed taxonomy into continuous monitoring tools to ensure real‑time alerts remain audit‑ready.

Source: DataBreachToday

Technical Notes

  • No new vulnerability or exploit disclosed; the change is purely nomenclature‑focused.
  • Google’s system pairs a “origin” word (e.g., Castle = China) with a contextual descriptor (e.g., Relic).

Source: same as above

📰 Original Source
https://www.databreachtoday.com/blogs/insane-castle-hurricane-apt-codename-confusion-proliferates-p-4162 ↗

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Vendor Risk Hub

This is the scenario continuous vendor monitoring is built to catch.

When a vendor is compromised, your third-party risk controls are what produce the audit trail showing you knew, assessed, and acted. The Verisq AI Trust Operations platform tracks that continuously.

Explore the Verisq AI Trust Operations platform →