Google has recently announced the creation of its own taxonomy to classify cybercriminal groups, a move that deliberately distances itself from the Microsoft-led effort to standardize threat actor names. The new nomenclature, introduced after integrating Mandiant into the Google Threat Intelligence Group (CTIG), aims to simplify the identification of malicious groups through a two-word scheme: the first word is a unique and memorable term, and the second classifies the cluster by motivation, attribution, or activity type. Although the initiative could bring clarity to a saturated ecosystem of aliases, it also reflects competitive tensions among tech giants vying for dominance in the threat intelligence market.
From a technical perspective, Google's decision to abandon the consensus pushed by Microsoft and CrowdStrike in 2025 stems from the need to align its internal taxonomy after the Mandiant acquisition. The company has defined categories such as CASTLE for Chinese groups, ION for Iranian, NEPTUNE for North Korean, RELIC for Russian, and COMET for non-state criminals. This system, while simpler, risks increasing fragmentation. For companies managing multiple security tools, the proliferation of names — like the ten aliases used for Russian intelligence unit 74455 — remains an operational challenge. In this context, having a technology partner that seamlessly integrates these data sources is crucial.
This is where Q2BSTUDIO adds value. As a company specializing in software development and technology, we offer solutions that enable organizations to consolidate threat intelligence through advanced cybersecurity services, including pentesting, monitoring, and incident response. Our ability to design custom applications that integrate with platforms like Google Cloud or Azure helps security teams correlate actor names and prioritize defenses. Additionally, we apply AI and intelligent agents to automate threat analysis, reducing manual workload and improving reaction times.
Google's taxonomy also sparks debate about geopolitical biases. China has already criticized names like 'Typhoon' or 'Panda' for stigmatizing its groups, while Google claims to generate random words to avoid prejudice. However, the industry needs interoperable standards. Companies adopting cloud solutions on AWS or Azure can benefit from environments that facilitate the integration of multiple threat intelligence feeds. At Q2BSTUDIO, we develop Business Intelligence platforms with Power BI that transform threat data into actionable dashboards, enabling executives to make informed decisions about cybersecurity investments.
Another relevant aspect is the evolution of AI agents. With the proliferation of groups like those classified as COMET (non-state criminals), automation becomes indispensable. Our teams design systems that use machine learning to detect attack patterns and recommend countermeasures, all integrated into custom applications tailored to each client's infrastructure. For example, we have implemented solutions that correlate Google Threat Intelligence alerts with internal logs, reducing false positives by 40%.
Beyond nomenclature, the real challenge is translating intelligence into defensive actions. Current fragmentation forces CISOs to maintain dedicated teams for mapping names across vendors. At Q2BSTUDIO, we offer technology consulting to design architectures that unify these feeds, using cloud AWS and Azure as a scalable foundation. Our approach combines proactive cybersecurity with Business Intelligence, creating a continuous improvement cycle. For instance, we integrate data from Mandiant, CrowdStrike, and Microsoft into a single repository, using Power BI to generate executive reports highlighting the most relevant threats for each sector.
Google's decision also has strategic implications for the market. By rejecting Microsoft's leadership, the company aims to position its intelligence ecosystem as the de facto standard. For businesses, this means evaluating which taxonomies their current tools will adopt and how to adapt. Our team at Q2BSTUDIO advises on selecting security platforms, ensuring that investments in AI, automation, and cloud align with real risks. Because in the end, beyond names, what matters is the ability to protect digital assets in an increasingly complex threat landscape.
In conclusion, Google's new taxonomy is a step toward simplification, but also a reminder that modern cybersecurity requires integration and customization. At Q2BSTUDIO, we help organizations navigate this fragmented landscape with custom applications that connect intelligence, cloud, and business. If your company seeks to strengthen defenses, explore the potential of AI, or consolidate threat data with Power BI, contact us. Security is not just a name; it is a continuous strategy.





