For more than a decade, the cybersecurity industry has been assigning names to different hacking groups. Some of them, like Fancy Bear, have crossed over into the mainstream because of their prominent hacks and memorable names. Others are only known within the cybersecurity industry.
Oftentimes, even industry insiders can’t keep track. In part, that’s because every company names hacking groups differently. That’s why there are resources like this one, which attempt to be a one-stop shop where cybersecurity professionals, government officials, policymakers, journalists, and the wider public can make sense of who is who.
Last month, Google became the latest company to revamp its naming system for hacking groups.
Gone are the days APT1, APT41 or APT whatever number, which was the system adopted by Mandiant, once an independent security firm that’s now part of Google. Mandiant was the first to adopt a naming scheme.
From now on, Google’s system is relatively simple: A hacking group will have a first name that is memorable and random, and a second word whose initial indicates the country of origin: Castle for China, Ion for Iran, Neptune for North Korea, and Relic for Russia.
According to Shane Huntley, the chief technology officer of Google Threat Intelligence Group, the company’s in-house hacker hunting team, the revamp was necessary to bring clarity to security researchers both inside the company and externally.
In the early 2010s, when companies started publishing reports on cyberattacks and naming the hackers behind them, Huntley told TechCrunch that, “we were not expecting to have as many threat groups as we do today.”
It had become hard to keep track of everyone. Google now tracks more than 5,000 “activity clusters” in several countries, according to John Hultquist, chief analyst at Google Threat Intelligence Group. Huntley said that there are very few developed nations that don’t have their own cyber capabilities and hacking groups.
But what is the point of naming hacking groups? It’s not just an academic exercise, Huntley explained. The goal is to have a baseline understanding of who is attacking who, and how they are attacking them. That way organizations can recognize threats more quickly, prepare against them, ideally stop them, or at least investigate incidents more promptly.
All that, he said, it’s possible only if you name the hackers and track them consistently.
... continue reading