Google’s top hacker hunter explains why hacking groups get codenames
Google recently changed how it refers and assigns names to hacking groups. TechCrunch spoke with one of the world’s foremost experts on tracking hackers to understand why companies give hackers codenames.
The naming of a threat actor is rarely an act of creativity. It is an act of classification, and classification is the first step toward control. Google's recent shift in how it assigns codenames to hacking groups is therefore not a cosmetic change. It is a quiet revision of how the industry organizes its understanding of adversaries.
For years, the security community has operated with a patchwork of naming conventions. One vendor calls a group by a weather pattern, another by a mineral, a third by a number. The same cluster of attackers can carry three or four identities across different reports, and the confusion serves no one except the attackers themselves. A codename, properly managed, collapses that noise into a single reference point. It gives analysts a shared vocabulary and gives executives a way to track a threat without needing to understand the underlying infrastructure.
The deeper function of a codename is memory. Human beings do not retain strings of IP addresses or hashes. They retain names. When a group is called Sandworm or Lazarus, it becomes a character in a story that security teams can follow over years. That narrative continuity matters because advanced persistent threats are not single events. They are campaigns that evolve, adapt, and return. A stable name allows the industry to connect the dots across incidents that might otherwise look unrelated.
There is also a strategic dimension. Naming a group is a form of attribution, and attribution is a form of deterrence. When a company publicly identifies and names an adversary, it signals that the adversary is being watched, that their methods are understood, and that their operations are no longer invisible. The name becomes a warning. It tells the group that their anonymity has been stripped away, and that future actions will be measured against a known history.
Google's decision to revise its own approach suggests that the current system has reached a limit. The old names may have become too scattered, too inconsistent, or too tied to a single vendor's internal logic. A new framework, applied uniformly, offers the chance to reset the baseline. It is an acknowledgment that the threat landscape has matured to the point where the industry's own language needs to mature with it.
None of this changes the fundamental reality of the work. The hackers will keep hacking, and the trackers will keep tracking. But the codename is the quiet infrastructure that makes the tracking possible. It is the label on the file, the marker on the map, the name on the case. Google's change is not about branding. It is about making the invisible visible, and making the visible manageable.