CuraSec

Learn archived

Google Threat Intelligence Group adopts unified actor naming schema

2026-07-25 12:08 UTC · Google Threat Intelligence · read the source ↗ #threat-intelligence#attribution#taxonomy
  • Engineer — Skip
  • SOC/IR — Learn: GTIG is merging Mandiant and TAG naming systems into a cryptonym-based taxonomy; analysts should update internal runbooks and intel mappings to cross-reference old identifiers (e.g. APT numbers) with new names as GTIG rolls out the change.
  • Leader — Skip
This entry was curated and judged by AI (Claude) with automated enrichment (CISA KEV / EPSS / public PoC). Verify against the original source before acting. Found a bad verdict? Report it — confirmed errors go to the corrections log.