Google Gives Hackers New Names, Here Is Why That Matters

Google's threat-intelligence team is replacing its old numbering system with memorable two-word labels for every hacking group it tracks, making it easier for researchers and companies to talk about the same criminals.

ThreatVectr Newsdesk· 3 min read
A close-up, sharply lit photograph of two printed pages lying side by side on a dark desk, one page covered in dense text and tables with several entries circle
Share

Key points

  • Google's threat-intelligence unit is switching from number codes like "APT44" to plain two-word names for every hacking group it follows.
  • The second word in each name signals where the group comes from or what drives it: "Relic" for Russia, "Castle" for China, "Ion" for Iran, "Neptune" for North Korea, and "Comet" for criminal gangs.
  • Russia's Sandworm, the hacking group blamed for attacks on power grids and election infrastructure, becomes "Sandworm Relic" under the new system.
  • Old names stay searchable inside Google's threat platform, so researchers who know a group by its previous label will not lose their place.
  • The change affects dozens of the most active groups now, with the rest to follow on a rolling basis.

If you follow cybersecurity news, you have probably noticed that the same group of hackers can carry five different names depending on which company wrote the report. Microsoft calls one Russian crew "Seashell Blizzard." Other researchers call the same crew "Sandworm," "Voodoo Bear," or "TeleBots." Google has been tracking them as "APT44," where APT stands for Advanced Persistent Threat, a label the industry uses for well-funded, government-linked hacking teams.

That alphabet soup is a real problem. It slows down defenders trying to piece together whether a fresh attack belongs to a group they already know about.

Google's answer is a new naming system built on two-word pairs. The first word is a memorable label tied to the specific group, often one already in circulation. The second word works like a category tag.

What do the new category words mean?

Each second word maps to an origin country or a motivation. Think of it as a surname that tells you where the group is from.

Second word What it signals
Relic Russia
Castle China
Ion Iran
Neptune North Korea
Comet Criminal (financially motivated) gangs

Groups that have not been firmly attributed to any country keep the "UNC" label, short for uncategorized, which Google has used for years.

Sandworm, the Russian military hacking crew held responsible for knocking out parts of Ukraine's electricity grid and for the destructive NotPetya malware attack in 2017, is the headline example. Google tracked this group as APT44; it now becomes Sandworm Relic. At least thirteen other names for the same crew float around the industry, reported SecurityWeek, which is a sign of exactly the problem Google is trying to fix.

Does this change anything for ordinary people?

Not directly. Renaming a hacking group does not make them less dangerous. What it does is make it easier for the security teams protecting hospitals, banks, and infrastructure to share information quickly and accurately.

Faster, clearer communication between defenders is a practical gain. When a company's security team reads an alert, the group's name now carries a built-in clue about who is behind the attack and roughly what they are after.

If you are a customer of a company that has been attacked by one of these groups, the advice stays the same: watch for unexpected emails asking for passwords, enable two-step verification on important accounts, and report anything suspicious to your IT team or bank.

© 2026 Threat Vectr