• Google Threat Intelligence Group is replacing its inherited Mandiant and TAG identifiers with two-word cryptonyms, starting with several dozen of its most-tracked groups
  • The second word encodes attribution or motive, with CASTLE for China, ION for Iran, NEPTUNE for North Korea, RELIC for Russia, and COMET for criminal crews not visibly tied to a particular country
  • The scheme standardizes naming inside Google but adds another convention to an industry that agreed on a shared alias mapping only last year

The Russian military intelligence crew that most of the security industry knows as Sandworm has picked up another name - it is Sandworm Relic, at least when Google is doing the talking.

Google Threat Intelligence Group has announced plans to retire the tangle of identifiers it inherited from two separate teams and replacing them with two-word cryptonyms, starting with several dozen of the groups it tracks most closely and continuing on a rolling basis.

Google has recently argued against its old approach of using sequential identifiers like APT1, on the grounds that a number tells a defender nothing about who they are dealing with. It has begun replacing them with a schema it says is more intuitive and makes it easier to determine where an attack comes from and what motivates it.

Rationalizing Google's need to change an already-established order

The mechanics are simple enough. Every tracked actor gets a pair of words. The first is meant to be distinctive and memorable, and where the security community has already settled on a moniker, Google says it will keep it. Where no such term exists, the word is generated at random to remove bias, then checked by analysts before it goes into use.

The second word does the categorizing, sorting clusters by motivation, attribution or activity type. The sample table Google published maps CASTLE to groups tied to the People's Republic of China, ION to Iran, NEPTUNE to North Korea, RELIC to Russia and COMET to financially motivated criminals.

The approach, as CyberScoop points out, closely echoes CrowdStrike's long-running practice of pairing a unique term with an animal keyed to country or motive: PANDA for China, BEAR for Russia, SPIDER for criminals, JACKAL for hacktivists. Google has simply swapped the animals for words like CASTLE and NEPTUNE.

The move is the latest step after Google announced its $5.4 billion acquisition of Mandiant in 2022, which it eventually combined with its in-house Threat Analysis Group to form GTIG.

The merger brought together two tracking systems that had evolved independently for years, meaning the same activity could appear under two different Google labels depending on which team wrote the report.

For now, Russia-linked Sandworm Relic is the only new name to have surfaced publicly, and Google is hardly the first to attempt this.

Microsoft has settled on weather, and countries such as China have publicly disputed the attributions sitting behind those labels. Google's move to "streamline" threat names could still make things simpler if it catches on with the rest of the world.

Alternatively, it could just add to the confusion in an industry where no standards are yet completely agreed upon. Google and Mandiant signed on to a Microsoft and CrowdStrike alias-mapping effort in June 2025, and The Register reported that sources at the time indicated both were keen to adopt the Microsoft-led scheme. Last week's announcement makes no mention of it. However good Google's intentions, defenders are still being handed one more system to learn.

Rahim Amir is a UAE-based tech writer who enjoys building PCs as much as he enjoys writing about them. He has been professionally writing about PC hardware since 2023, focusing on buyer’s guides, hardware reviews, and sponsored content and features related to tech.

Having built hundreds of gaming PCs and being an avid gamer in his spare time, Rahim tends to have stronger opinions about hardware than most. This is particularly on display when he gets his way with powerful, but minimalistic RGB builds even as Small Form Factor (SFF) PCs come a close second.