{"id":61153,"date":"2026-07-27T07:31:00","date_gmt":"2026-07-27T07:31:00","guid":{"rendered":"https:\/\/www.theregister.com\/a\/5278749"},"modified":"2026-07-27T07:31:00","modified_gmt":"2026-07-27T07:31:00","slug":"google-goes-it-alone-with-a-new-cybercrime-crew-taxonomy","status":"publish","type":"post","link":"https:\/\/www.threatshub.org\/blog\/google-goes-it-alone-with-a-new-cybercrime-crew-taxonomy\/","title":{"rendered":"Google goes it alone with a new cybercrime crew taxonomy"},"content":{"rendered":"<div><img decoding=\"async\" src=\"https:\/\/image.theregister.com\/255057.jpg?imageId=255057&amp;x=0&amp;y=0&amp;cropw=100&amp;croph=100&amp;panox=0&amp;panoy=0&amp;panow=100&amp;panoh=100&amp;width=1200&amp;height=683\" class=\"ff-og-image-inserted\"><\/div>\n<div data-element-guid=\"d11159dd-82a3-4c53-901c-d41dec75505c\" readability=\"31.12955465587\">\n<p class=\"kicker \">Security<\/p>\n<p class=\"subtitle \">So much for Microsoft and CrowdStrike\u2019s plans for consistent names across the industry<\/p>\n<\/p><\/div>\n<div data-element-guid=\"4c9dc5d9-c886-4348-bf4a-01d0dc71377d\" readability=\"94.19874715262\">\n<p>Google has created a new taxonomy to describe cybercrime outfits, seemingly abandoning a Microsoft-led effort to create consistent names.<\/p>\n<p>The Big G <a href=\"https:\/\/cloud.google.com\/blog\/topics\/threat-intelligence\/updated-cyber-threat-actor-naming-system\/\" target=\"_blank\">announced<\/a> its new schema on Saturday in a post that notes its <a href=\"https:\/\/www.theregister.com\/security\/2022\/09\/12\/google-cloud-acquires-mandiant-for-54bn\/1008803\" target=\"_blank\">2022 acquisition of Mandiant<\/a> and its subsequent incorporation into a new team called the Google Threat Intelligence Group (CTIG).<\/p>\n<p>Now that two have become one, Google reckons they need consistent naming conventions to describe cybercrime crews.<\/p>\n<p>The result is a two-word schema in which the first word \u201cis a unique and memorable term chosen to represent the specific actor.\u201d If security folk have already applied a particular moniker Google will use it, otherwise it will randomly generate a word \u201cto remove bias.\u201d<\/p>\n<div data-element-guid=\"afe083ca-6701-48e9-9bd8-f8827dd7fb42\" class=\"lab4 column articleList layout_vertical imageLayout_left small-12 large-4 small-abs-12 large-abs-4 abs_grid_4 desktop-floatLeft mobile-floatLeft grid-vas-start mobile-grid-vas-start\">\n<div class=\"content border_width_0 border_width_mobile_0 border-radius-48 border-radius-mobile_48\">\n<h2 class=\"article-list-title t19 font-RobotoCondensed\">MORE CONTEXT<\/h2>\n<\/p><\/div>\n<\/div>\n<p>Google says the second word \u201ccategorizes threat clusters by motivation, attribution, or activity type based on which category we consider to be most important for defense and response strategies.\u201d<\/p>\n<p>More on that later.<\/p>\n<p>Google has decided on the following names:<\/p>\n<ul readability=\"1\">\n<li readability=\"-1\">\n<p><span class=\"font-weight-bold m-font-weight-bold \" data-lab-font_weight=\"font-weight-bold\">CASTLE<\/span> to describe crews from the&nbsp;People\u2019s Republic of China<\/p>\n<\/li>\n<li readability=\"-1\">\n<p><span class=\"font-weight-bold m-font-weight-bold \" data-lab-font_weight=\"font-weight-bold\">ION<\/span> for threats from Iran<\/p>\n<\/li>\n<li readability=\"-1\">\n<p><span class=\"font-weight-bold m-font-weight-bold \" data-lab-font_weight=\"font-weight-bold\">NEPTUNE<\/span> for North Korean attackers<\/p>\n<\/li>\n<li>\n<p><span class=\"font-weight-bold m-font-weight-bold \" data-lab-font_weight=\"font-weight-bold\">RELIC<\/span> for Russians<\/p>\n<\/li>\n<li readability=\"-1\">\n<p><span class=\"font-weight-bold m-font-weight-bold \" data-lab-font_weight=\"font-weight-bold\">COMET<\/span><span>&nbsp;for cybercrims who aren&#8217;t backed by a state<\/span><\/p>\n<\/li>\n<\/ul>\n<p>Google\u2019s post notes that other infosec industry players have developed their own schemas for describing threat actors and says the web giant is therefore \u201cintentionally seeking to keep this system as simple as possible to streamline operations and facilitate mapping to other naming taxonomies.\u201d<\/p>\n<p>That\u2019s an odd position, given that in 2025 Microsoft and CrowdStrike tried to <a href=\"https:\/\/www.theregister.com\/security\/2025\/06\/03\/microsoft-et-al-pledge-clarity-on-cybercrew-names-hmph\/379496\" target=\"_blank\">spark an industry-wide effort<\/a> to apply consistent names to threat actors. As we noted at the time, the existence of multiple naming schemas means that researchers often refer to the same group by ten different names. Researchers use the names Seashell Blizzard, IRIDIUM, VOODOO BEAR, BE2, UAC-0113, Blue Echidna, PHANTOM, BlackEnergy Lite, and APT44 to refer to the same entity \u2013 Russia&#8217;s Military Intelligence Unit 74455.<\/p>\n<p>With most orgs using multiple security tools and therefore receiving threat intelligence security info from many vendors, users must try to understand which crews they\u2019re trying to defend against.<\/p>\n<p>At the time, sources told us Google and Mandiant were keen to adopt the Microsoft-led scheme.<\/p>\n<p>Google\u2019s new announcement suggest the relationship either wasn\u2019t consummated or didn\u2019t last.<\/p>\n<p>Back to the issue of possible bias, as in 2024 China&#8217;s National Computer Virus Emergency Response Center (CVERC) <a href=\"https:\/\/www.theregister.com\/security\/2024\/10\/15\/china-again-claims-volt-typhoon-was-invented-by-the-us\/604449\">complained<\/a> that western companies choose names like \u201cTyphoon,\u201d \u201cPanda,\u201d or \u201cDragon\u201d to describe Chinese cybercrime groups.<\/p>\n<p>CVERC suggested names that reflect English language idioms, such as \u201cHurricane\u201d or \u201cKoala\u201d are more appropriate.<\/p>\n<p>For what it\u2019s worth, \u201cKoala\u201d is a word from the language spoken by the Darug people, the indigenous tribe who lived around Sydney, Australia, prior to British colonization. Koalas are utterly supine creatures that sleep 18 to 22 hours a day, and a mention of the marsupials may therefore not spur defenders to action, even if the creatures\u2019 habits do perhaps describe the behavior of some sleeper malware. \u00ae<\/p>\n<\/p><\/div>\n<p><img decoding=\"async\" src=\"https:\/\/image.theregister.com\/?imageId=255057&#038;width=800\">READ MORE <a href=\"https:\/\/www.theregister.com\/security\/2026\/07\/27\/google-goes-it-alone-with-a-new-cybercrime-crew-taxonomy\/5278749\">HERE<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p> So much for Microsoft and CrowdStrike\u2019s plans for consistent names across the industry READ MORE HERE&#8230;<\/p>\n","protected":false},"author":2,"featured_media":61154,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"colormag_page_layout":"default_layout","footnotes":""},"categories":[63],"tags":[307],"class_list":["post-61153","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-the-register","tag-security"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.1 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Google goes it alone with a new cybercrime crew taxonomy 2026 | ThreatsHub Cybersecurity News<\/title>\n<meta name=\"description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.threatshub.org\/blog\/google-goes-it-alone-with-a-new-cybercrime-crew-taxonomy\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Google goes it alone with a new cybercrime crew taxonomy 2026 | ThreatsHub Cybersecurity News\" \/>\n<meta property=\"og:description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.threatshub.org\/blog\/google-goes-it-alone-with-a-new-cybercrime-crew-taxonomy\/\" \/>\n<meta property=\"og:site_name\" content=\"ThreatsHub Cybersecurity News\" \/>\n<meta property=\"article:published_time\" content=\"2026-07-27T07:31:00+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/image.theregister.com\/255057.jpg?imageId=255057&amp;x=0&amp;y=0&amp;cropw=100&amp;croph=100&amp;panox=0&amp;panoy=0&amp;panow=100&amp;panoh=100&amp;width=1200&amp;height=683\" \/>\n<meta name=\"author\" content=\"TH Author\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@threatshub\" \/>\n<meta name=\"twitter:site\" content=\"@threatshub\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"TH Author\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"3 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/google-goes-it-alone-with-a-new-cybercrime-crew-taxonomy\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/google-goes-it-alone-with-a-new-cybercrime-crew-taxonomy\\\/\"},\"author\":{\"name\":\"TH Author\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\"},\"headline\":\"Google goes it alone with a new cybercrime crew taxonomy\",\"datePublished\":\"2026-07-27T07:31:00+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/google-goes-it-alone-with-a-new-cybercrime-crew-taxonomy\\\/\"},\"wordCount\":522,\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/google-goes-it-alone-with-a-new-cybercrime-crew-taxonomy\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/07\\\/google-goes-it-alone-with-a-new-cybercrime-crew-taxonomy.jpg\",\"keywords\":[\"Security\"],\"articleSection\":[\"The Register\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/google-goes-it-alone-with-a-new-cybercrime-crew-taxonomy\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/google-goes-it-alone-with-a-new-cybercrime-crew-taxonomy\\\/\",\"name\":\"Google goes it alone with a new cybercrime crew taxonomy 2026 | ThreatsHub Cybersecurity News\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/google-goes-it-alone-with-a-new-cybercrime-crew-taxonomy\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/google-goes-it-alone-with-a-new-cybercrime-crew-taxonomy\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/07\\\/google-goes-it-alone-with-a-new-cybercrime-crew-taxonomy.jpg\",\"datePublished\":\"2026-07-27T07:31:00+00:00\",\"description\":\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/google-goes-it-alone-with-a-new-cybercrime-crew-taxonomy\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/google-goes-it-alone-with-a-new-cybercrime-crew-taxonomy\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/google-goes-it-alone-with-a-new-cybercrime-crew-taxonomy\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/07\\\/google-goes-it-alone-with-a-new-cybercrime-crew-taxonomy.jpg\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/07\\\/google-goes-it-alone-with-a-new-cybercrime-crew-taxonomy.jpg\",\"width\":100,\"height\":50},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/google-goes-it-alone-with-a-new-cybercrime-crew-taxonomy\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Security\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/tag\\\/security\\\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"Google goes it alone with a new cybercrime crew taxonomy\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"name\":\"ThreatsHub Cybersecurity News\",\"description\":\"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"alternateName\":\"Threatshub.org\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\",\"name\":\"ThreatsHub.org\",\"alternateName\":\"Threatshub.org\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"width\":432,\"height\":435,\"caption\":\"ThreatsHub.org\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/x.com\\\/threatshub\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\",\"name\":\"TH Author\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"caption\":\"TH Author\"}}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Google goes it alone with a new cybercrime crew taxonomy 2026 | ThreatsHub Cybersecurity News","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.threatshub.org\/blog\/google-goes-it-alone-with-a-new-cybercrime-crew-taxonomy\/","og_locale":"en_US","og_type":"article","og_title":"Google goes it alone with a new cybercrime crew taxonomy 2026 | ThreatsHub Cybersecurity News","og_description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","og_url":"https:\/\/www.threatshub.org\/blog\/google-goes-it-alone-with-a-new-cybercrime-crew-taxonomy\/","og_site_name":"ThreatsHub Cybersecurity News","article_published_time":"2026-07-27T07:31:00+00:00","og_image":[{"url":"https:\/\/image.theregister.com\/255057.jpg?imageId=255057&amp;x=0&amp;y=0&amp;cropw=100&amp;croph=100&amp;panox=0&amp;panoy=0&amp;panow=100&amp;panoh=100&amp;width=1200&amp;height=683","type":"","width":"","height":""}],"author":"TH Author","twitter_card":"summary_large_image","twitter_creator":"@threatshub","twitter_site":"@threatshub","twitter_misc":{"Written by":"TH Author","Est. reading time":"3 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.threatshub.org\/blog\/google-goes-it-alone-with-a-new-cybercrime-crew-taxonomy\/#article","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/google-goes-it-alone-with-a-new-cybercrime-crew-taxonomy\/"},"author":{"name":"TH Author","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476"},"headline":"Google goes it alone with a new cybercrime crew taxonomy","datePublished":"2026-07-27T07:31:00+00:00","mainEntityOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/google-goes-it-alone-with-a-new-cybercrime-crew-taxonomy\/"},"wordCount":522,"publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/google-goes-it-alone-with-a-new-cybercrime-crew-taxonomy\/#primaryimage"},"thumbnailUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2026\/07\/google-goes-it-alone-with-a-new-cybercrime-crew-taxonomy.jpg","keywords":["Security"],"articleSection":["The Register"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/www.threatshub.org\/blog\/google-goes-it-alone-with-a-new-cybercrime-crew-taxonomy\/","url":"https:\/\/www.threatshub.org\/blog\/google-goes-it-alone-with-a-new-cybercrime-crew-taxonomy\/","name":"Google goes it alone with a new cybercrime crew taxonomy 2026 | ThreatsHub Cybersecurity News","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/google-goes-it-alone-with-a-new-cybercrime-crew-taxonomy\/#primaryimage"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/google-goes-it-alone-with-a-new-cybercrime-crew-taxonomy\/#primaryimage"},"thumbnailUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2026\/07\/google-goes-it-alone-with-a-new-cybercrime-crew-taxonomy.jpg","datePublished":"2026-07-27T07:31:00+00:00","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","breadcrumb":{"@id":"https:\/\/www.threatshub.org\/blog\/google-goes-it-alone-with-a-new-cybercrime-crew-taxonomy\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.threatshub.org\/blog\/google-goes-it-alone-with-a-new-cybercrime-crew-taxonomy\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/google-goes-it-alone-with-a-new-cybercrime-crew-taxonomy\/#primaryimage","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2026\/07\/google-goes-it-alone-with-a-new-cybercrime-crew-taxonomy.jpg","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2026\/07\/google-goes-it-alone-with-a-new-cybercrime-crew-taxonomy.jpg","width":100,"height":50},{"@type":"BreadcrumbList","@id":"https:\/\/www.threatshub.org\/blog\/google-goes-it-alone-with-a-new-cybercrime-crew-taxonomy\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.threatshub.org\/blog\/"},{"@type":"ListItem","position":2,"name":"Security","item":"https:\/\/www.threatshub.org\/blog\/tag\/security\/"},{"@type":"ListItem","position":3,"name":"Google goes it alone with a new cybercrime crew taxonomy"}]},{"@type":"WebSite","@id":"https:\/\/www.threatshub.org\/blog\/#website","url":"https:\/\/www.threatshub.org\/blog\/","name":"ThreatsHub Cybersecurity News","description":"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform","publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"alternateName":"Threatshub.org","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.threatshub.org\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.threatshub.org\/blog\/#organization","name":"ThreatsHub.org","alternateName":"Threatshub.org","url":"https:\/\/www.threatshub.org\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","width":432,"height":435,"caption":"ThreatsHub.org"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/x.com\/threatshub"]},{"@type":"Person","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476","name":"TH Author","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","caption":"TH Author"}}]}},"_links":{"self":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/61153","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/comments?post=61153"}],"version-history":[{"count":0,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/61153\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media\/61154"}],"wp:attachment":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media?parent=61153"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/categories?post=61153"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/tags?post=61153"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}