Google Overhauls Its Threat Actor Naming System With Sandworm Relic

Google’s threat intelligence unit has stopped calling Russia’s most disruptive military-linked hacking group APT44. Starting this week, analysts tracking the crew blamed for blackouts in Ukraine and the NotPetya worm will find it filed under a new name: Sandworm Relic.

The rebrand comes from Google Threat Intelligence Group (GTIG, the unit Google built by merging Mandiant’s threat-intelligence practice with its own in-house Threat Analysis Group), which is retiring sequential codes and scattered aliases in favor of two-word cryptonyms. Outside researchers already track that one Russian cluster under thirteen separate names, exactly the kind of duplication GTIG says it wants to end. The fix also lands thirteen months after Google itself joined a coalition built to cut the number of competing naming systems, not add to it.

Sandworm Trades a Serial Number for a Cryptonym

The formula is simple by design. The first word is a distinct, memorable term, often one already floating around in public reporting, and a randomly generated one when nothing fits. The second word sorts the actor into a category based on motivation, attribution or activity type.

Google has published five of those category words so far:

  • Castle – threat actors linked to China
  • Ion – threat actors linked to Iran
  • Neptune – threat actors linked to North Korea
  • Relic – threat actors linked to Russia
  • Comet – financially motivated cybercrime gangs

Sandworm becomes Sandworm Relic under that scheme. GTIG has applied new cryptonyms to several dozen of its most active tracked groups so far, with the rest following on a rolling basis. Google said in its announcement that it wants the system to stay simple enough to streamline its own operations and to make mapping against other vendors’ names easier, not harder.

Thirteen Aliases for One Blackout Squad

The scale of the duplication problem is easy to see in Sandworm’s own case file. Within the security community, the same activity cluster has also gone by Blue Echidna, Electrum, FrozenBarents, Iridium, Iron Viking, Quedagh, Seashell Blizzard, TEMP.Noble, TeleBots, Voodoo Bear and several UAC-prefixed labels used by Ukrainian responders.

That is not an isolated case.

  • 13 aliases already track Sandworm across the security industry, on top of its old APT44 designation and new Sandworm Relic name.
  • A dozen or more names also exist for APT28, the Russian group best known as Fancy Bear, according to Microsoft and CrowdStrike’s own joint mapping work.
  • Several dozen threat actors received new cryptonyms in Google’s first wave, with more scheduled on a rolling basis.

Google said its visibility into the threat landscape, like every vendor’s, is necessarily partial, which is what keeps apples-to-apples comparisons between threat actors difficult in most cases. Its own framing was blunt: transitioning to a convention that is simpler to follow and remember is a practical step toward managing a highly intricate tracking problem.

A Mandiant Legacy Folds Into the Parent Brand

The APT-plus-number format that produced APT44 was not originally Google’s. Mandiant, the incident-response firm Google acquired and later folded into GTIG alongside its own Threat Analysis Group, popularized that numbering system and built much of its reputation on it.

Retiring APT44 for Sandworm Relic is not just a cosmetic swap. It is the moment Mandiant’s own independent tracking brand gets absorbed fully into Google’s house style. The UNC prefix survives the transition for now: Google will keep using it for clusters that have not yet been sorted into a category by motivation or origin, a holdover from Mandiant’s own convention for unattributed activity.

CrowdStrike Already Wrote This Playbook

Google’s two-word structure is not new to the industry. CrowdStrike has run a near-identical format for years, pairing a chosen prefix with an animal suffix tied to a nation or motive: Panda for China, Bear for Russia, Kitten for Iran, Chollima for North Korea and Spider for financially motivated crews. Microsoft made a similar bet in 2023, when it retired its chemical-element and family-based labels for weather-themed names tied to each hacker’s home country or motive.

Lined up side by side, the convergence is obvious:

Region or Motive Google GTIG Microsoft CrowdStrike
China Castle Typhoon Panda
Russia Relic Blizzard Bear
Iran Ion Sandstorm Kitten
North Korea Neptune Sleet Chollima

CrowdStrike has described its own approach as combining marketing potential with geographic information in a company explainer on why adversary names matter to defenders. Google’s system runs on the same logic: a catchy handle up front, a category tag on the back end. Microsoft’s own North Korea-linked family made news of its own this year when the company tied Sapphire Sleet to the Mastra npm supply chain attack, a reminder that these labels are not just taxonomy, they show up in active incident response.

The Coalition Google Signed Onto Last Year

Here is the part that complicates Google’s simplification pitch. In June 2025, Microsoft and CrowdStrike announced a joint mapping of overlapping threat actor names meant to cut through exactly this kind of confusion. Palo Alto Networks and Google’s own Mandiant unit agreed to join that broader effort on streamlining threat group taxonomy.

Thirteen months later, instead of consolidating onto that shared glossary, Google rolled out a brand-new, Google-only naming system. The two efforts are not in conflict on paper. Google says previous names, including MITRE ATT&CK mappings and other vendors’ aliases, stay indexed and searchable inside the Google Threat Intelligence (GTI) platform. But defenders now have Google’s cryptonyms, Microsoft’s weather names, CrowdStrike’s animals, MITRE’s own group IDs and a cross-vendor glossary meant to tie them all together, all running at once.

What Changes Inside the Security Operations Center?

For working analysts, the immediate change is mostly cosmetic: old identifiers keep working in search, detection rules built around legacy names do not need to be ripped out overnight, and Google says it plans to preserve cross-references as it renames more clusters.

The bigger adjustment is habitual. Threat reports, training material and internal runbooks written around APT44 now need a parallel reference to Sandworm Relic, at least until muscle memory catches up. Google’s rolling rollout means that adjustment will repeat dozens of times over, not just once, as more legacy IDs get retired in favor of the new format.

Frequently Asked Questions

What is Google Threat Intelligence Group?

GTIG is the unit Google built by combining Mandiant’s threat-intelligence practice with its in-house Threat Analysis Group. It publishes the Google Threat Intelligence platform that customers and researchers use to track hacking activity and now maintains the new cryptonym naming system.

Why does one hacking group end up with a dozen different names?

Rival vendors, government agencies and independent researchers often discover and name the same activity cluster separately, sometimes years apart, before anyone realizes they are looking at the same group. Sandworm alone carries thirteen outside aliases on top of its old Mandiant designation.

Will old identifiers like APT44 stop working in search?

No. Google said previous names remain indexed and searchable inside the GTI platform, with MITRE ATT&CK mappings and other vendors’ aliases preserved alongside each new cryptonym.

Is Google’s new system connected to the Microsoft-CrowdStrike naming glossary?

Loosely. Mandiant agreed in 2025 to join the mapping coalition led by Microsoft and CrowdStrike, but the new cryptonym system is a separate, Google-only taxonomy that runs alongside that shared glossary rather than replacing it.

What happens to threat actors that have not been renamed yet?

They keep their existing identifiers for now. Google is renaming clusters on a rolling basis, starting with several dozen of its most active tracked groups, and will keep using the UNC prefix for activity it has not yet sorted by motivation or origin.

Leave a Reply

Your email address will not be published. Required fields are marked *