Skip to content
RiverCore
Google Rewrites 22 Years of Threat Actor Names in One Schema
threat actor namingGTIG schemaAPT renamingGoogle GTIG cryptonym naming schema 2026SANDWORM RELIC APT44 name change

Google Rewrites 22 Years of Threat Actor Names in One Schema

26 Jul 20266 min readSarah Chen

Six aliases. That's how many public names the Russian state group known as APT44 has picked up since 2004: Dark Basin, Frozenbarents, Greyenergy, Hades, Inedibleochotense, and Quedagh, plus the "Sandworm" moniker most defenders actually use. As of July 25, 2026, Google Threat Intelligence Group has collapsed that mess into two words: SANDWORM RELIC. The rename is the visible tip of a much larger schema overhaul that every downstream consumer of Google threat feeds now has to reconcile against their own tooling.

What Happened

GTIG announced a unified cryptonym-based naming schema on July 25, 2026, designed to standardize how the combined organization tracks threat actors. As Cyber Press reported, the change directly addresses the fragmentation left behind when Mandiant merged with Google's Threat Analysis Group (TAG). The two teams had operated separate, independently evolved tracking systems for years, and the merger that created GTIG exposed the structural problem of maintaining two parallel naming conventions in one org.

The new format is deliberately simple. Every actor gets a two-word cryptonym. The first word is a unique identifier, ideally pulled from prior public reporting where an established name already exists. When no established term is available, GTIG generates a randomized word and runs it through analyst review to catch bias or accidental offense. The second word is a category label signaling motivation, attribution, or activity type. Under this convention, APT44/Sandworm becomes SANDWORM RELIC, where RELIC signals Russian state attribution.

GTIG is prioritizing renames for several dozen of the most active threat groups first, then processing additional actors on a rolling basis. Legacy names remain indexed and searchable in the Google Threat Intelligence (GTI) platform alongside preserved MITRE ATT&CK mappings and third-party vendor aliases. GTIG also flagged an explicit caveat: no two organizations share identical visibility into the threat landscape, so cross-vendor comparisons remain inherently imprecise. The team framed the schema as a practical improvement, not a definitive solution to attribution itself.

Technical Anatomy

The engineering problem here is a classic entity-resolution one, applied to threat intelligence rather than customer records or ad IDs. Pre-merger, Mandiant's APT-numbered catalog and TAG's internal identifiers were two different primary key spaces pointing at overlapping (but not identical) sets of real-world entities. A defender ingesting both feeds ended up doing manual reconciliation: is Mandiant's APT44 the same operational cluster as whatever TAG called it internally? Sometimes yes, sometimes partially, sometimes the clusters diverged based on which telemetry each team had.

Sequential numbering like "APT1" carries zero semantic payload. The name tells you nothing about attribution, motivation, or activity type, so analysts have to memorize a lookup table or grep documentation every time a new alert fires. The two-word cryptonym embeds a category label directly into the identifier. RELIC = Russian state. If GTIG publishes the full suffix taxonomy (the source doesn't disclose the complete category dictionary, which matters because downstream tooling will need to hardcode or pull that mapping), analysts can infer attribution context from the name alone without hitting the platform.

The backward-compatibility design is the part that will keep enterprise integrations from breaking. Legacy identifiers stay indexed in GTI. MITRE ATT&CK mappings persist. Third-party vendor aliases are preserved. In practical terms this means a SIEM rule keyed on "APT44" should still resolve to the same actor record when queried against GTI, and correlation across CrowdStrike, Microsoft, or Recorded Future naming (each with their own conventions) still has a hop path.

What we don't know yet: whether the cryptonym is exposed as an additional field in STIX/TAXII exports or whether it replaces the primary identifier in feed payloads. That distinction determines whether existing detection pipelines silently keep working or start dropping records. Bound on impact: if GTIG treats cryptonyms as a new field and preserves legacy IDs in the same object, integration cost is close to zero. If cryptonyms become the canonical primary key, expect a multi-quarter migration across every SOC that consumes GTI.

Who Gets Burned

Three groups feel this most immediately. First, SOC teams running detection rules or SOAR playbooks that reference threat actor names as strings. Every rule that pattern-matches "APT44" or "Sandworm" in an enrichment field now needs to also match "SANDWORM RELIC" or the ingestion layer needs to normalize on the fly. That's a documentation and testing exercise, not a hard engineering problem, but it's real work across several dozen priority groups in the first wave.

Second, threat intelligence vendors and MSSPs who resell or repackage Google intel. Their customer-facing reports, dashboards, and API contracts likely reference the old names. The rolling rename schedule means their content pipeline needs a translation layer for months, not weeks, as GTIG works through the long tail of less-active groups.

Third, and this is where TRAFFIC-adjacent teams should pay attention: fraud and abuse teams inside ad platforms, affiliate networks, and iGaming operators who track state-linked or financially motivated groups for ad fraud, credential stuffing, and account takeover attribution. If your fraud analytics stack ingests threat actor labels to score incidents, the label vocabulary just shifted underneath you. Anyone who built dashboards that group incidents by attributed actor over rolling 12-month windows will see apparent discontinuities that are actually just rename artifacts.

Historical reporting is the second-order problem. Every threat brief, board deck, and post-mortem from the last decade references legacy names. New hires reading old documentation will need the alias table open in another tab. GTIG's decision to preserve legacy indexing in GTI mitigates this, but only for customers with active GTI subscriptions. Teams relying on free public reporting or archived vendor blogs get no such compatibility layer.

Playbook for Performance Marketing

Performance and growth teams don't typically own threat intel, but ad fraud, affiliate abuse, and account security do intersect. Concrete actions for this week:

Audit any internal doc, runbook, or Looker/Tableau dashboard that references threat actor names as literal strings. Grep for "APT" followed by digits. Anywhere those appear, add a note flagging the rename schedule and set a review date.

If your fraud stack pulls from GTI or resells threat intel that references GTI actors, open a ticket with your vendor now asking two questions: are cryptonyms exposed as an additional field or as a replacement, and what's their translation SLA. The source doesn't disclose GTIG's export format changes, so vendor answers will vary.

For teams building attribution reporting under Privacy Sandbox or similar frameworks, this is a useful reminder that identifier stability across vendor systems is never free. The same reconciliation discipline applies to actor names, campaign IDs, and user cohort labels.

Testable prediction: if the rollout follows GTIG's stated rolling schedule, we should see the several dozen priority groups renamed within the next two quarters, and downstream SIEM vendors publishing translation mappings within 60 to 90 days of the announcement. If translation mappings haven't shipped by end of Q3 2026, expect visible detection gaps in customer environments that pull from multiple feeds.

Key Takeaways

  • GTIG replaced APT-style numbering with two-word cryptonyms on July 25, 2026. APT44/Sandworm is now SANDWORM RELIC, with RELIC signaling Russian state attribution.
  • Legacy names stay indexed and searchable in GTI alongside MITRE ATT&CK mappings and third-party aliases, preserving backward compatibility for existing integrations.
  • Several dozen priority actors get renamed first, with the long tail on a rolling schedule. Expect months, not weeks, for full coverage.
  • Unknown and worth watching: whether cryptonyms are added as a new field in feed exports or replace the primary identifier. That single design choice determines whether SIEM pipelines keep working silently or need migration work.
  • GTIG explicitly acknowledged that cross-vendor naming comparisons remain imprecise because no two orgs share identical visibility. The new schema is a usability fix, not an attribution breakthrough.

Frequently Asked Questions

Q: What is the new Google threat actor naming convention?

GTIG assigns each threat actor a two-word cryptonym. The first word is a unique identifier, ideally drawn from prior public reporting, and the second is a category label indicating motivation, attribution, or activity type. Example: APT44/Sandworm is now SANDWORM RELIC, where RELIC signals Russian state attribution.

Q: Do legacy threat actor names still work in Google Threat Intelligence?

Yes. GTIG confirmed that previous identifiers remain indexed and searchable within the GTI platform, alongside preserved MITRE ATT&CK framework mappings and aliases used by other vendors. This preserves backward compatibility for analysts referencing historical reporting.

Q: Which threat groups get renamed first?

GTIG is prioritizing several dozen of the most active threat groups in the initial wave, with additional actors renamed on a rolling basis afterward. The source does not publish the full priority list, so security teams should monitor GTI updates directly to track when specific actors relevant to their environment get reclassified.

SC
Sarah Chen
RiverCore Analyst · Dublin, Ireland
SHARE
// RELATED ARTICLES
HomeSolutionsWorkAboutContact
News06
Dublin, Ireland · EUGMT+1
LinkedIn
🇬🇧EN▾