Security News

Cybersecurity news aggregator

INFO News SC Media

Google introduces new cybercrime naming taxonomy, diverging from Microsoft's initiative

  • What: Google introduces new cybercrime naming taxonomy
  • Impact: Industry shift in how threat actors are categorized and named
Read Full Article →

Threat Management , Threat Intelligence Google introduces new cybercrime naming taxonomy, diverging from Microsoft’s initiative July 28, 2026 Share By SC Staff (Adobe Stock) The Register reports that Google unveiled its own taxonomy for categorizing cybercrime groups, a move that appears to sideline a previous industry-wide effort led by Microsoft to standardize threat actor names. Google's new system, developed by the Google Threat Intelligence Group following its acquisition of Mandiant, uses a two-word schema. The first word is a unique identifier for the actor, either an existing moniker or a randomly generated term to avoid bias. The second word categorizes the group by motivation, attribution, or activity type. Google has assigned specific terms such as CASTLE for China-based groups, ION for Iran, NEPTUNE for North Korea, RELIC for Russia, and COMET for non-state-sponsored actors. This approach contrasts with a 2025 initiative by Microsoft and CrowdStrike aimed at creating a unified naming convention. The proliferation of multiple naming schemas, as seen with the numerous names used for Russian threat actor APT44, complicates threat intelligence analysis for organizations using diverse security tools. Google's decision to create its own system, despite previous indications of interest in the Microsoft-led effort, suggests a divergence in strategy. The company cited concerns about bias in naming, referencing past complaints from China regarding Western companies' naming conventions for Chinese cybercrime groups. Source: The Register SC Staff Related Malware Malicious Steam workshop map delivered malware to MECCHA CHAMELEON players SC Staff July 28, 2026 As outlined in Cyber Insider, a malicious Steam Workshop map for the game MECCHA CHAMELEON exploited a vulnerability in the game's mod-loading system to deliver malware to players' computers. Threat Management Russian hackers exploited Zimbra zero-day in espionage campaigns SC Staff July 27, 2026 Russian state-sponsored cybercriminals exploited a zero-day vulnerability in the Zimbra email and collaboration platform to conduct espionage against Western targets, primarily military and government agencies, according to a recent report by Tech Radar. Security Operations The enduring mystery of hacker Phineas Fisher SC Staff July 27, 2026 As outlined in TechCrunch, the enigmatic hacker known as Phineas Fisher remains one of the most elusive and impactful figures in cybersecurity, a decade after their most notorious exploits. Related Events Cybercast Better Threat Intelligence Between Public and Private Sectors On-Demand Event Cybercast RSAC Preview: Exposure management takes center stage On-Demand Event Virtual Conference Nationwide Cybersecurity Summit 2025: Safeguarding America’s Digital Future On-Demand Event Get daily email updates SC Media's daily must-read of the most current and pressing daily news Business Email By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy . Subscribe Related Terms Account Harvesting Backdoor Denial of Service Dictionary Attack Distributed Scans Domain Hijacking Dumpster Diving Google Hacking Hybrid Attack Password Cracking You can skip this ad in 5 seconds

Share this article