Google Threat Intelligence launches cryptonym naming scheme and pushes behavioral analytics for zero‑day detection
Google’s Threat Intelligence Group reported tracking 90 zero‑day vulnerabilities exploited in 2025, with nearly half aimed at enterprise technology. To improve detection of such unseen threats, the group is advocating for behavioral analytics in endpoint security, which establishes baselines of normal user activity and flags anomalous actions such as unexpected locations, devices, or times.
In parallel, Google announced a new two‑word cryptonym system for the threat actors it monitors, replacing prior identifiers inherited from Mandiant and its own TAG team. The first word is a unique label, while the second denotes attribution or motive: CASTLE for Chinese groups, ION for Iran, NEPTUNE for North Korea, RELIC for Russian actors, and COMET for financially motivated criminal crews. For example, the Russian intelligence crew known as Sandworm will appear as Sandworm Relic. The change aims to make naming more intuitive and align with industry practices.
Entities: Google Threat Intelligence Group · Mandiant · Sandworm Relic