Why Google’s Hacker Renaming Affects Your SME
You run a small business in Malaysia. You have a team, a handful of suppliers, and a growing list of customers. When a headline says Google changed how it names hacking groups, your first thought is probably: “That has nothing to do with my shop.” It actually does.
Security researchers don’t name hacking groups for fun. They do it to track behaviour, patterns, and history — so the next attack can be spotted sooner. That intelligence eventually reaches you, through the email provider you use, the bank you transact with, and the cloud tools you depend on. When the naming system gets clearer, your protection gets better.
What Happened
Last month, Google revamped its naming system for hacking groups. The era of labels like APT1 and APT41 — the scheme popularised by Mandiant, now part of Google — is over. In its place is a simpler convention: each hacking group gets a memorable random first name, followed by a second word whose starting letter indicates the country of origin: Castle for China, Ion for Iran, Neptune for North Korea, and Relic for Russia.
Shane Huntley, chief technology officer of Google Threat Intelligence Group, says the change was overdue. In the early 2010s, when security firms began publishing reports on attackers, “we were not expecting to have as many threat groups as we do today,” he told TechCrunch. Google now tracks more than 5,000 “activity clusters” across several countries, according to John Hultquist, chief analyst at Google Threat Intelligence Group. Huntley added that very few developed nations lack their own cyber capabilities.
| New Google Suffix | Country |
|---|---|
| Castle | China |
| Ion | Iran |
| Neptune | North Korea |
| Relic | Russia |
Why bother naming groups at all? Huntley’s answer is practical. Naming gives defenders a baseline understanding of who attacks whom and how. Organisations can then recognise threats faster, prepare against them, and investigate incidents more quickly. Take the Lazarus Group, the North Korean state-backed hackers. Knowing who they are, what they typically want, and how they usually operate gives defenders a starting point — even when every attack can’t be prevented.
Why This Matters for Malaysian SMEs
You might think “APT” tracking is a corporate concern, not a small business one. Malaysian SMEs are increasingly digital: you take orders through WhatsApp, handle e-invoices, pay suppliers via online banking, and store customer data in cloud inboxes. Attackers know this. Hacking groups don’t check a company’s headcount before phishing an employee or testing a weak password. What they look for is access — and smaller firms often have fewer layers of protection.
When Google unifies the naming scheme across its old Threat Analysis Group and Mandiant, at least there is one fewer scheme to remember. More importantly, the clarity helps the vendors you already rely on. Your email security, bank app, and cloud providers use threat intelligence feeds that track these groups. Cleaner naming means fewer duplicate entries and blind spots in those feeds, so warnings reach you sooner and with more context.
“If you actually get hacked by them or you’re dealing with some incident, knowing how that actor behaves, what they do, what they’ve done in the past, all of these details become critically important to help the response and also work out your coverage against these threats as well.” — Shane Huntley, CTO, Google Threat Intelligence Group
That quote says it all for a business in Kuala Lumpur, Penang, or Johor Bahru. Imagine a staff member receives an urgent invoice from an overseas supplier. Whether your team flags it depends on recognising a known pattern — like a group that impersonates vendors during payment periods. The codename is just a handle; the behaviour behind it is the real defence. When researchers can agree on who is who, the warnings that reach you become more specific and less generic.
The Bigger Picture
One obvious question: why can’t all security companies just use the same names? Huntley says that’s unavoidable. “No one has perfect visibility,” he explained. Every company sees a slightly different slice of a hacking group’s activity, based on its own data and telemetry, so merging taxonomies is easier said than done. For a Malaysian SME, that means you don’t need to memorise codenames or follow threat reports. Your job is simpler:
- Treat unsolicited requests for login credentials or bank transfers as suspicious, even when they appear to come from your boss or a known supplier.
- Keep software, phones, and backups updated — detection tools only help when the underlying systems are patched.
- Ask your IT vendor or cloud provider where their threat intelligence comes from, and whether they monitor groups active in Southeast Asia.
- Report incidents to CyberSecurity Malaysia so local threat intelligence improves for every business.
Google’s change won’t stop hackers. But it reflects a broader truth: the industry is trying to make sense of a landscape that has grown far beyond early expectations. More than 5,000 tracked clusters isn’t a sign of order — it’s a sign of how crowded the battlefield has become. For you, the practical takeaway is not the codenames. It’s the behaviour behind them. Pay attention to patterns, not labels. That is the defence that scales with your business.
Ready to Streamline Your Operations?
Technology moves fast. Your operations should keep up. AutoRunBiz builds AI systems that run your daily workflows — from WhatsApp order capture to accounting. Book a free 15-min ops audit →
