Only one outlet has reported this event so far — you're reading it below, credited to its source. AIPROPX is tracking the web for more coverage; as additional outlets confirm it, this becomes a full multi-source story automatically.
By AIPROPX Editorial Desk · Published · Updated
One outlet is reporting this so far. AIPROPX is tracking it and will gather every additional source as it develops — the full multi-source comparison appears automatically once a second outlet confirms it.

Google Threat Intelligence Group is replacing its inherited Mandiant and TAG identifiers with two-word cryptonyms, starting with several dozen of its most-tracked groups
The second word encodes attribution or motive, with CASTLE for China, ION for Iran, NEPTUNE for North Korea, RELIC for Russia, and COMET for criminal crews not visibly tied to a particular country
The scheme standardizes naming inside Google but adds another convention to an industry that agreed on a shared alias mapping only last year
The Russian military intelligence crew that most of the security industry knows as Sandworm has picked up another name - it is Sandworm Relic, at least when Google is doing the talking.
Google Threat Intelligence Group has announced plans to retire the tangle of identifiers it inherited from two separate teams and replacing them with two-word cryptonyms, starting with several dozen of the groups it tracks most closely and continuing on a rolling basis.
Google has recently argued against its old approach of using sequential identifiers like APT1, on the grounds that a number tells a defender nothing about who they are dealing with. It has begun replacing them with a schema it says is more intuitive and makes it easier to determine where an attack comes from and what motivates it.
Rationalizing Google's need to change an already-established order
The mechanics are simple enough. Every tracked actor gets a pair of words. The first is meant to be distinctive and memorable, and where the security community has already settled on a moniker, Google says it will keep it. Where no such term exists, the word is generated at random to remove bias, then checked by analysts before it goes into use.
The second word does the categorizing, sorting clusters by motivation, attribution or activity type. The sample table Google published maps CASTLE to groups tied to the People's Republic of China, ION to Iran, NEPTUNE to North Korea, RELIC to Russia and COMET to financially motivated criminals.
The approach, as CyberScoop points out, closely echoes CrowdStrike's long-running practice of pairing a unique term with an animal keyed to country or motive: PANDA for China, BEAR for Russia, SPIDER for criminals, JACKAL for hacktivists. Google has simply swapped the animals for words like CASTLE and NEPTUNE.
The move is the latest step after Google announced its $5.4 billion acquisition of Mandiant in 2022, which it eventually combined with its in-house Threat Analysis Group to form GTIG.
The merger brought together two tracking systems that had evolved independently for years, meaning the same activity could appear under two different Google labels depending on which team wrote the report.
For now, Russia-linked Sandworm Relic is the only new name to have surfaced publicly, and Google is hardly the first to attempt this.
Microsoft has settled on weather, and countries such as China have publicly disputed the attributions sitting behind those labels . Google's move to "streamline" threat names could still make things simpler if it catches on with the rest of the world.
Alternatively, it could just add to the confusion in an industry where no standards are yet completely agreed upon. Google and Mandiant signed on to a Microsoft and CrowdStrike alias-mapping effort in June 2025, and The Register reported that sources at the time indicated both were keen to adopt the Microsoft-led scheme. Last week's announcement makes no mention of it. However good Google's intentions, defenders are still being handed one more system to learn.
Indexed and credited by AIPROPX. Originating outlet: TechRadar. Open at source →
An original, deterministic readout — composed only from the computed coverage facts on this page. No interpretation, no rating; figures only.
AIPROPX has consolidated 1 report from 1 outlet into a single canonical entry on “Google has a new way of talking about the latest cyber threats — so get ready for a whole load of crazy new names.” Every covered outlet is based in Other.
The only timestamped report came from TechRadar (Jul 29, 2026, 23:20 UTC).
2 statements are carried by only one outlet within this set and are not echoed by the others.
Every figure above is a direct count of real published articles. AIPROPX indexes and compares the original reporting — it never rewrites, rates, or editorializes — and each publisher’s full article is always one click away.
Generated by AIPROPX from the source counts above. AIPROPX indexes and resolves coverage; the original publishers are credited and linked at origin in every report.
Coverage from 1 independent outlet across 1 region — each view opens on its own page.
AIPROPX — “Google has a new way of talking about the latest cyber threats — so get ready for a whole load of crazy new names” · https://www.aipropx.com/story/a6bae9b446e522ccba84dc34aa59a135
Other events being covered across multiple sources right now.
Wisconsin judge says voters who have returned absentee ballot for state primary cannot get a new one
5 outletsIt's going to do things that currently are impossible': The Roman Space Telescope, NASA's next great observatory, is ready to…
5 outletsAbout Town
4 outletsSanta Clara County Has Its First 2 West Nile Virus Cases of 2026
4 outletsJeff Passan Names 5 Teams in the Tarik Skubal Sweepstakes
3 outletsEthereum Foundation names pcaversaccio to board amid leadership changes