Popular Posts

Cybersecurity Industry Grapples with Hacking Group Nomenclature as Google Revamps Naming System

For more than a decade, the cybersecurity industry has been grappling with the complex and often confusing task of assigning names to the myriad of hacking groups operating globally. This practice, initially intended to bring clarity, has paradoxically led to a patchwork of nomenclature where different companies use their own unique systems, making it challenging even for industry insiders to keep track. While some groups, like the notorious Fancy Bear, have garnered mainstream recognition due to their high-profile attacks and memorable monikers, countless others remain known only within specialized cybersecurity circles.

The inherent difficulty arises from the fact that every security firm and intelligence agency develops its own internal tracking and naming conventions. This decentralization often results in a single threat actor being known by multiple names across different reports and analyses, creating significant confusion. To address this persistent problem, resources like the MITRE ATT&CK knowledge base have emerged as critical tools. These platforms strive to serve as a comprehensive, centralized repository, helping cybersecurity professionals, government officials, policymakers, journalists, and the wider public to make sense of the intricate web of cyber adversaries and their activities. By cataloging adversary tactics, techniques, and common knowledge, MITRE ATT&CK provides a common language and framework, even if the primary names for groups still vary.

Recognizing this ongoing challenge, Google became the latest major player last month to revamp its naming system for hacking groups. This significant overhaul, detailed in a blog post, aims to streamline and clarify the identification of threat actors, particularly given the ever-increasing number of groups the company tracks.

The previous system, notably adopted by Mandiant—an independent security firm now integrated into Google’s operations—relied heavily on the "APT" (Advanced Persistent Threat) designation followed by a number, such as APT1 or APT41. Mandiant was a pioneer in establishing a naming scheme in the early 2010s, and its APT numbering system became widely recognized, if not always intuitively understood. However, as the landscape of cyber threats evolved and the number of identified groups exploded, a sequential numerical system proved increasingly unwieldy and lacked descriptive power. It offered little immediate insight into the nature or origin of the threat, relying solely on prior knowledge of the associated number.

Google’s new approach is designed for simplicity and memorability. Under the revamped system, a hacking group will be assigned a two-word name. The first word will be memorable and randomly chosen, aiming for distinctiveness. The second word is crucial, as its initial letter will directly indicate the group’s country of origin. For instance, "Castle" signifies China, "Ion" points to Iran, "Neptune" indicates North Korea, and "Relic" identifies Russia. This standardized approach intends to provide immediate, at-a-glance information about a group’s likely affiliation, fostering quicker understanding and categorization among security researchers and analysts.

Shane Huntley, the chief technology officer of the Google Threat Intelligence Group and the head of the company’s in-house hacker hunting team, emphasized the necessity of this revamp. He told TechCrunch that the primary goal was to bring much-needed clarity to security researchers, both within Google’s extensive ecosystem and externally across the broader cybersecurity community. Huntley reflected on the early 2010s, when companies first began publishing reports on cyberattacks and attempting to name the perpetrators. At that time, he noted, "we were not expecting to have as many threat groups as we do today." The sheer proliferation of actors has overwhelmed older, less scalable naming conventions.

Indeed, the scale of the cyber threat landscape has grown exponentially. John Hultquist, chief analyst at Google Threat Intelligence Group, revealed that Google now actively tracks over 5,000 "activity clusters" across numerous countries. These clusters represent distinct groups or campaigns, each with its own characteristics and objectives. Huntley further underscored the ubiquity of cyber capabilities, stating that very few developed nations today do not possess their own sophisticated cyber units and associated hacking groups, highlighting the global nature of this digital arms race.

But beyond the mere act of identification, what is the fundamental purpose of naming hacking groups? Huntley clarified that it is far from an academic exercise. The core objective is to establish a foundational understanding: "who is attacking who, and how they are attacking them." This baseline comprehension is critical for several practical reasons. Armed with consistent and clear naming, organizations can recognize specific threats more quickly, enabling them to prepare against potential attacks proactively. Ideally, this understanding can help to stop attacks before they succeed or, failing that, allow for more prompt and effective investigation of incidents once they occur.

Huntley stressed that the ability to achieve these defensive outcomes hinges entirely on consistently naming and tracking threat actors. He elaborated on the tangible benefits, explaining that "if you actually get hacked by them or you’re dealing with some incident, knowing how that actor behaves, what they do, what they’ve done in the past, all of these details become critically important to help the response and also work out your coverage against these threats as well." For example, understanding the typical tactics, techniques, and procedures (TTPs) of the North Korean government-backed Lazarus Group—a notorious entity known for its financial heists and destructive attacks—provides defenders with a vital starting point. Knowing their usual targets, their modus operandi, and their ultimate objectives allows security teams to anticipate their moves, shore up relevant defenses, and interpret anomalous network behavior within a known context.

While tracking state-sponsored hackers like the Lazarus Group is challenging, Huntley explained that it is generally more manageable than monitoring cybercriminal groups or hackers-for-hire. Government-backed actors tend to exhibit more consistent targets and activities, often aligning with national strategic interests. Their operational structures are typically more stable, and their campaigns, while varied, often follow predictable patterns linked to specific geopolitical events or intelligence gathering priorities.

Conversely, cybercriminal groups are far more amorphous and fluid. Their membership can fluctuate, individuals may join and leave different factions, and groups often splinter or re-form under new guises. Their motivations are predominantly financial, leading to a broader, less predictable range of targets and attack methods. Similarly, hacker-for-hire groups and developers of commercial spyware operate with a diverse client base across different parts of the world, making their activities harder to pinpoint and attribute consistently. Their services are available to a variety of customers, complicating efforts to track a singular objective or pattern of behavior.

A common and understandable criticism that surfaces whenever a new naming system is announced is: "Why can’t all companies and organizations simply agree to use the same codenames?" While this seems like an easy solution on the surface, the reality, according to Huntley, is far more complex. Every security company and intelligence agency possesses a slightly different perspective on each group, largely because their views are shaped by their unique sets of data, telemetry, and intelligence collection capabilities. No single entity has perfect visibility into the entirety of a threat actor’s operations.

Huntley described this as an inescapable reality that cannot be fully overcome simply by sharing more information among companies and research groups. "No one has perfect visibility," he stated. "We are building our model and our best understanding, but we will never know everything about what’s going on." This fundamental limitation means that while collaboration is vital, a truly universal, perfectly synchronized naming system remains an elusive goal. Each organization’s "truth" about a threat actor is constructed from its specific vantage point.

Nevertheless, Google’s recent unification of the naming schemes used by its old Threat Analysis Group (which Huntley previously headed) and Mandiant represents a significant step forward. By merging these two prominent systems, at least one fewer distinct naming convention exists for researchers to navigate. For all other instances of disparate naming and the ongoing challenge of cross-referencing, the gargantuan list maintained by MITRE ATT&CK continues to serve as an indispensable resource, guiding the cybersecurity community through the ever-expanding lexicon of global cyber threats. This ongoing effort to bring order to the naming chaos is crucial for enhancing collective defense in an increasingly digital and dangerous world.

Leave a Reply

Your email address will not be published. Required fields are marked *