Google Unveils Independent Cybercrime Group Taxonomy, Diverging from Industry Efforts
Google's Threat Intelligence Group has introduced a novel two-word taxonomy for categorizing cybercrime actors, opting for an independent approach that deviates from prior industry-wide naming initiatives.

Google has introduced a new, two-word taxonomy for classifying cybercrime groups, a move that appears to set it apart from previous collaborative efforts within the cybersecurity industry. This new schema, developed by the newly formed Google Threat Intelligence Group (CTIG) following the integration of Mandiant, aims to provide a consistent and simplified method for identifying and understanding threat actors.
The taxonomy consists of two components. The first word is a unique, memorable identifier chosen to represent a specific actor. Google states that if a moniker is already widely recognized and applied by the security community, it will be adopted. Otherwise, a random word will be generated to mitigate potential bias. The second word categorizes the threat cluster based on its primary motivation, attribution, or activity type, prioritizing the aspect most crucial for defense and response strategies.
Examples provided by Google include CASTLE for Chinese state-sponsored groups, ION for Iranian actors, NEPTUNE for North Korean entities, RELIC for Russian threat actors, and COMET for non-state cybercriminal organizations. This structured approach is intended to streamline operations and facilitate mapping to other existing naming conventions.
This initiative marks a departure from earlier attempts to standardize threat actor nomenclature. In 2025, Microsoft and CrowdStrike spearheaded an effort to establish a unified naming system, recognizing the confusion caused by multiple, often overlapping, designations for the same groups. Researchers frequently encounter the same actor referred to by numerous different names, complicating threat intelligence analysis and defensive measures.
Google's decision to forge its own path is notable, especially given that both Google and Mandiant were reportedly interested in adopting the Microsoft-led scheme prior to their full integration. The divergence suggests a strategic choice by Google to maintain greater control over its threat intelligence categorization or a reassessment of the collaborative approach.
The move also touches upon the sensitive issue of naming bias. Concerns have been raised in the past, such as China's National Computer Virus Emergency Response Center (CVERC) criticizing Western companies for using culturally charged or potentially demeaning names for Chinese cybercrime groups. Google's stated intention to use randomly generated words when existing monikers are unavailable aims to address such criticisms and remove subjective bias from the naming process.
While Google emphasizes simplicity and operational streamlining, the existence of multiple, independent taxonomies—including this new one from Google alongside others from Microsoft, CrowdStrike, and various research firms—means that organizations will continue to face the challenge of correlating threat intelligence from different sources. The effectiveness of Google's new system will ultimately depend on its adoption by the broader security community and its ability to accurately and consistently reflect the evolving threat landscape.