Google's Threat Intelligence Group has overhauled its naming system for tracked hacking groups, replacing the old numbered APT designations with descriptive codenames tied to specific nation-state actors. The change is not cosmetic. Mandiant's John Hultquist, one of the most cited threat intelligence analysts in the field, explains the operational logic behind why the industry names hackers at all.
The core argument: codenames create shared language across vendors, governments, and victims. When CrowdStrike says Fancy Bear and Google says APT28, coordination breaks down. Standardized naming collapses that friction. The article goes deeper than the rebrand, tracing how attribution decisions get made, what level of confidence is required before a name sticks, and why getting it wrong has real geopolitical consequences.
The full interview with Hultquist is worth reading for its explanation of how analysts distinguish between groups with overlapping tooling, and how naming a group publicly can actually degrade an adversary's operational security by forcing them to retool. That mechanism alone changes how you think about threat intelligence as an offensive lever, not just a defensive one.
[READ ORIGINAL →]