Google Introduces New Naming Conventions for State-Sponsored and Cybercrime Actors
In a significant step towards addressing the complexities of cybersecurity nomenclature, Google has unveiled a new system for classifying threat actors. This initiative aims to simplify how state-sponsored and cybercriminal groups are identified, offering new names such as Castle, Ion, Neptune, Relic, and Comet. Each of these terms is strategically crafted to categorize various actors based on their affiliations with countries such as China, Iran, North Korea, and Russia.
Critics have raised questions regarding the necessity of introducing yet another set of designations, highlighting the existing confusion already prevalent in the field of threat intelligence. The industry has been saturated with various names for the same groups, to the extent that even well-known entities like APT44, which is linked to Russia’s military intelligence service (the GRU), already possesses at least thirteen different aliases. Google’s designation for this particular group is "Sandworm Relic," underscoring the challenges in maintaining clarity amidst a plethora of naming conventions.
Google’s newly implemented system uses a two-part naming structure, where the first word indicates origin or type, and the second name reflects the group’s motivation or type of activity. This categorization has been described by Google as a necessary method to streamline operations and facilitate easier mapping to other existing taxonomies. In a blog post from the Google Threat Intelligence group, the firm emphasized its intent to simplify the recognition process, indicating, "Relying on sequential numbers or disparate identifiers (e.g., APT1) fails to provide defenders the critical context needed to operate quickly." This statement highlights a shift away from previously utilized methods that may lack the intuitive understanding necessary for effective defense strategies.
The rationale behind Google’s new naming convention is to harmonize two existing in-house naming strategies: one developed by Google’s threat intelligence team and the other from Mandiant, an incident response firm acquired by Google in 2022. Understanding this backdrop raises essential points about the consolidation of naming systems in the cybersecurity realm. Why not utilize one of the numerous schemes already available? Veteran security researcher Daniel Cuthbert expressed his bewilderment regarding the industry’s failure to establish a common ground. He voiced a compelling argument for the need for standards, stressing that the proliferation of different names for the same entities complicates the landscape, making it increasingly challenging for professionals to navigate.
Google is not alone in its endeavors to create a unique naming convention for threat actors. Earlier in 2023, Microsoft launched its weather-themed taxonomy, generating terms like Typhoon for actors associated with China and Blizzard for those linked to Russia. Trend Micro also entered the fray with its novel approach, deriving names from classical elements and mythical creatures, with the ransomware group LockBit being referred to as "Water Selkie."
Adding to the debate, Google’s representatives noted that the reason for not adopting existing naming systems is that no organization can achieve an equal visibility of the threat landscape. They posited that direct comparisons between threat actors are often not feasible. However, critics have warned that the distinct naming conventions employed by tech giants may serve more as marketing tactics than practical solutions. There exists a perception that these cutesy names risk minimizing the severity of the actions carried out by malicious actors who engage in activities causing significant disruption, anguish, and even loss of life.
Prominent voices in the cybersecurity community, such as Jen Easterly, a former head of the U.S. Cybersecurity and Infrastructure Security Agency (CISA), have argued passionately against these whimsical labels. Easterly emphasized the necessity to regard these adversaries’ activities for what they truly are: preparations for war. Another former CISA official, Brandon Wales, echoed this sentiment, asserting that vague terms can blur the gravity of the threats posed by foreign military and intelligence operations that risk undermining critical infrastructure.
The growing complexity and confusion in threat actor naming are somewhat acknowledged as a systemic issue that has persisted over the years. Independent researchers and organizations, like the Malware Information Sharing Platform (MISP), have endeavored to mitigate these challenges through community-driven initiatives. MISP’s efforts to establish a standardized approach are indicative of the pressing need for a cohesive framework in the industry.
Alexandre Dulaunoy, a researcher contributing to MISP, has pointed out that the ongoing introduction of new names for already identified threat actors continues to complicate matters. His foresight underscores a crucial reality: many organizations still refrain from utilizing universally accepted identifiers, leading to further confusion among cybersecurity experts.
In conclusion, Google’s introduction of a new naming convention reflects broader challenges in the field of cybersecurity. While the intention behind these changes may be to enhance clarity and operational efficiency, the resulting confusion indicates a pressing need for industry-wide standards that can unite various perspectives. As the threat landscape evolves, so too must the methods of identifying and categorizing the actors within it, ensuring that those on the frontline of cybersecurity can respond to threats without the hindrance of unwieldy nomenclature. This issue of naming standardization, therefore, remains critical to fostering a united front in the ongoing battle against cybercrime.
