Visualização de leitura

2,000 Leaked Documents Reveal How Russia Turns Engineering Students Into GRU Cyber Operators

2,000 leaked files expose Bauman University’s hidden Department No. 4, which trained GRU-linked hackers and propagandists linked to APT28 and Sandworm.

Leaked Documents Expose Bauman University’s Hidden Department That Trained Hackers, Propagandists, and Malware Developers for the GRU

More than 2,000 internal documents from Bauman Moscow State Technical University have been reviewed by an international media consortium, and the picture they describe is not a conventional cybersecurity program. The files span academic and administrative records through 2025.

“Recently leaked records show that Bauman Moscow State Technical University’s Department No. 4 operated as a long-term training pipeline for Russian military intelligence and cyber operations.” reads the report published by DomainTools. “The department served several elements of the Russian General Staff and trained roughly 250 career and reserve students across three specialties: special intelligence (“Служба специальной разведки”), operational information-technical effects (“Применение сил и средств информационно-технического воздействия и защиты от информационно-технического воздействия”), and information-technology protection (”3ащита информационных технологий”). “

Department No. 4, also called “Special Training,” operated inside Bauman’s Military Training Center and doesn’t appear anywhere on the university’s public organizational chart. The GRU’s talent pipeline tends not to announce itself.

The investigation was carried out by a group of media outlets including The Insider, The Guardian, Le Monde, Der Spiegel, Delfi, VSquare, and FRONTSTORY.PL. DomainTools researchers also analyzed the leaked files independently. A DarkForums user known as “Losyash” may have shared the data, but it has not been confirmed that the account originally obtained the records.

The department trained students in three military specialties. These covered special intelligence, information and cyber operations, and the protection of IT systems. In practice, the courses included espionage, offensive cyber operations, electronic reconnaissance, secure systems, and influence operations.

Around 250 career and reserve students went through the program over six academic years. Researchers estimate that 10 to 15 students each year were selected for GRU-related assignments before graduating.

“Technical protection training covered cryptography and steganography, as well as code analysis and intrusion detection. Students were also trained in hardware inspection, the discovery of physical implants, and the identification of undocumented device functions. These subjects point to possible assignments in technical counterintelligence and supply chain security, as well as firmware analysis and embedded system inspection. Other likely functions include secure procurement and the protection of specialized military platforms.” continues the report. “The files also reveal an underreported malware-analysis and cyber threat intelligence program.”

One advanced practical assignment required the creation of a social-media video built around what the course materials called “manipulation, pressure, and hidden propaganda.” This counted as coursework.

Course materials defined “information-technical weapons” as tools and methods designed to alter, destroy, copy, block, or manipulate information. Red-team and blue-team functions were treated as a single discipline, not separate tracks, which mirrors how Russian military doctrine actually deploys cyber operators.

The personnel links are what make this more than a training curiosity. The leaked records identify Major General Viktor Netyksho as involved in Department No. 4’s oversight. Netyksho was the former commander of Military Unit 26165, the GRU formation publicly associated with APT28, also tracked as Fancy Bear, Sofacy, and STRONTIUM. He was among the 12 GRU officers indicted by the United States in 2018 for interference in the 2016 presidential election.

Reporting identified graduates assigned to GRU Military Unit 26165 (associated with APT28) and Military Unit 74455 (associated with Sandworm), and linked senior officers, including former Unit 26165 commander Viktor Netyksho, to student oversight.” continues the report. “The data also connected senior GRU officers to the supervision and evaluation of Bauman students. Viktor Netyksho, the former commander of Unit 26165 and the 85th Main Special Service Center, is part of the department’s teaching and oversight structure.”

The reporting also identifies Aleksei Kondrashov, a 2024 Department No. 4 graduate, as linked to Military Unit 74455: the GRU’s Main Center for Special Technologies, known publicly as Sandworm, or APT44. That unit has been associated with the 2017 NotPetya attack and ongoing destructive operations against Ukraine. DomainTools also connected graduates and senior staff to Military Unit 29155, a GRU formation linked to sabotage and assassination operations in Europe.

A necessary precision: the reports establish unit placements, not individual operational involvement. A documented assignment to Military Unit 74455 doesn’t establish that a specific person participated in a specific attack. That distinction matters for both attribution work and legal proceedings.

What the leak does establish is the factory behind the names. APT28 and Sandworm are the threat groups that security teams track, attribute, and brief about. Department No. 4 is where some of the people running those operations were systematically trained, assessed, and selected.

For defenders, DomainTools summarizes the implication precisely: Russian operations should be tracked as a combined threat in which espionage, destructive attacks, military reconnaissance, technical surveillance, and influence campaigns draw on the same personnel pipelines and the same underlying doctrine. The Bauman material makes that pipeline visible for the first time at this level of institutional detail.

“The documents show that Department No. 4 is a small part of a larger long-term military training system, not a single hacking unit. The program prepared personnel for espionage and offensive cyber operations within a larger Russian technical university system.” concludes the report. “Its doctrine treated cyber warfare as more than network intrusion. Students were taught not only adversarial cyber warfare, but also a larger holistic doctrine of cyber war using both defense and attack to be better able to carry out successful campaigns.”

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, Russia)

Smashing Security podcast #479: How a fake police officer nearly stole Graham’s cryptocurrency

Graham gets a phone call from the police. Well, someone who sounds convincingly like the police. There's just one small problem: what they really want is the 24-word seed key to Graham's cryptocurrency wallet. Meanwhile, if you've stayed in a hotel recently, the free Wi-Fi you connected to might have come with an unexpected extra: an all-you-can-eat buffet of "Captive Crunch" for a Russian intelligence-linked hacking group. And a group calling itself the "ExFilSquad" has walked off with 600,000 records of the UK's teachers and head teachers from the Department for Education — sending an unusually polite ransom demand. All this and more in episode 479 of the "Smashing Security" podcast with cybersecurity expert and keynote speaker Graham Cluley, and special guest Danny Palmer.

Smashing Security podcast #467: How ShinyHunters hacked the world’s biggest universities

Welcome to the largest educational data breach in history - affecting nearly 9,000 institutions, every Ivy League university, and 30 million students mid-finals. When Canvas's parent company refused to pay and announced they had deployed "security patches" instead, the hackers were less than impressed. So they came back through the cat flap. Meanwhile, a famous finance expert's face has been showing up on Facebook adverts promising hot stock tips and exclusive WhatsApp investment groups. Spoiler: it isn't him, the tips aren't real, and you're about to be scammed. Plus we chat to Mike Nichols of Elastic, about how the SOC isn't dying, attackers and defenders are both deploying AI agents, and how the real security crisis is no longer human users - it's the bots acting on their behalf. All this and more in episode 467 of the "Smashing Security" podcast with cybersecurity expert and keynote speaker Graham Cluley, and special guest Danny Palmer.

AI Agents Present ‘Insider Threat’ as Rogue Behaviors Bypass Cyber Defenses: Study

Artificial intelligence (AI) agents, once touted as the next frontier of corporate efficiency, are increasingly exhibiting deceptive and rogue behaviors that could overwhelm traditional cybersecurity. New research shows autonomous systems are now capable of collaborating to smuggle sensitive data, forge credentials, and even peer-pressure other AIs into bypassing safety protocols. According to findings from Irregular,..

The post AI Agents Present ‘Insider Threat’ as Rogue Behaviors Bypass Cyber Defenses: Study appeared first on Security Boulevard.

❌