Aggregator
Updated Cyber Threat Actor Naming System
Today, Google Threat Intelligence Group (GTIG) will begin rolling out a unified naming schema for tracking threat actors. This new naming taxonomy represents an effort to standardize tracking across platforms and public reporting.
Why are we Adopting a Different Naming System?Historically, Mandiant and Google’s Threat Analysis Group (TAG) maintained distinct tracking systems, relying on parallel naming schemas that grew independently over time. The creation of GTIG has necessitated a new, fused tracking system, and a new naming system. Thinking to the future, GTIG’s new system will rely on cryptonyms. Relying on sequential numbers or disparate identifiers (e.g. APT1) fails to provide defenders the critical context needed to operate quickly. Threat tracking shouldn’t be an exercise in memorization, but rather one of intuition. The new naming convention aligns with industry standard threat actor naming systems.
Our New SchemaOur new schema utilizes a cryptonym-based approach, employing memorable two-word combinations for each distinct threat actor:
-
The first word is a unique and memorable term chosen to represent the specific actor, particularly names that may have been used in prior public reporting. If no previously used term exists, this word is randomly generated to remove bias, then vetted by our analysts.
-
The second word categorizes threat clusters by motivation, attribution, or activity type based on which category we consider to be most important for defense and response strategies.
The table below provides a sample of how threat actor categories will map to the second word in each cryptonym:
Origin or Type
Group Name
People’s Republic of China
CASTLE
Iran
ION
North Korea
NEPTUNE
Russia
RELIC
Cybercriminal
COMET
Table 1: Examples of Google’s new threat actor naming system categories
We know there are many threat actor tracking schemas in the industry, so we are intentionally seeking to keep this system as simple as possible to streamline operations and facilitate mapping to other naming taxonomies. However, a significant caveat remains: because no two organizations have the exact same visibility into the threat landscape, direct, apples-to-apples comparisons between threat actors are rarely possible. Transitioning to a convention that is simpler to follow and remember is a practical step toward managing a highly intricate tracking problem.
A Work in ProgressWe have initially prioritized renaming several dozen of the most active groups, and will continue this process on a rolling basis. Previous names will remain indexed and searchable in the Google Threat Intelligence (GTI) platform, with MITRE ATT&CK mappings and other vendor aliases preserved, see Figure 1.
Figure 1: Threat actor name appearance in GTI platform on initial rollout
We will continue to use UNC, or “uncategorized” designations for threat clusters that are still in the early stages of investigation, as described here.
Foxit PDF Reader Flaw Lets Local Attackers Gain SYSTEM Privileges via DLL Sideloading
A recently disclosed vulnerability in Foxit PDF Reader may allow a local attacker with existing code execution to elevate their privileges to NT AUTHORITY\SYSTEM. This issue, tracked as CVE-2026-57239, affects Foxit PDF Reader installations prior to version 2026.2 and arises from the insecure handling of an updater workflow triggered by a user-writable file in the […]
The post Foxit PDF Reader Flaw Lets Local Attackers Gain SYSTEM Privileges via DLL Sideloading appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
Cl0p Targets Internet-Exposed Windchill Servers in Global Engineering Data-Theft Campaign
Cl0p ransomware affiliates are actively exploiting internet-exposed PTC Windchill and FlexPLM deployments in a global data-theft campaign targeting high-value engineering environments. Observed post-exploitation activity includes filesystem enumeration via files such as “flst.txt,” followed by staging and exfiltration of sensitive engineering and product design data. This chaining enables unauthenticated remote code execution, allowing attackers to deploy […]
The post Cl0p Targets Internet-Exposed Windchill Servers in Global Engineering Data-Theft Campaign appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
The Good, the Bad and the Ugly in Cybersecurity – Week 30
Vatican's Official Prayer App Leaks 700K+ Global Users' PII
Illinois Man Pleads Guilty to Phishing 4,500 Snapchat Users to Steal Private Photos
An Illinois man has pleaded guilty to a phishing and account-compromise scheme that targeted thousands of Snapchat users, leading to the theft of private images from numerous women. Federal prosecutors stated that Kyle Svara, 27, of Oswego, Illinois, admitted to charges including aggravated identity theft, wire fraud, computer fraud, conspiracy to commit computer fraud, and […]
The post Illinois Man Pleads Guilty to Phishing 4,500 Snapchat Users to Steal Private Photos appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.