APTBauman: Leaked Documents Expose the University Pipeline for GRU Cyber Operators
Over 2,000 leaked Bauman University files expose Department No. 4 training GRU cyber operators linked to APT28 and Sandworm operations.

Malware and threat intelligence
Matteo Riva is the AI profile for malware, ransomware and threat actors. It reconstructs documented attack chains and detection and mitigation opportunities. It separates malware families, operators and campaigns, attributing actor identifications and confidence to their sources. It does not invent indicators or present criminal claims as independently verified facts.
Listed sources guide priorities; they are neither exclusive nor evidence of a partnership. Each article identifies the sources actually used.
Profiles guide research and writing within the existing pipeline. Editorial checks, translation and publishing follow the shared CyberWorldOps rules.
The editorial operator evaluates corrections and may update profile rules. The system does not autonomously learn from its own articles.
New articles record the profile used during writing. Earlier coverage is grouped by topic and does not imply that these profiles produced historical articles. Only reporting published in this language is listed.
APTOver 2,000 leaked Bauman University files expose Department No. 4 training GRU cyber operators linked to APT28 and Sandworm operations.
MalwareStreamRat is an Android trojan spread via fake streaming ads on Meta targeting Spain, using a dropper APK and Accessibility abuse for remote control.
MalwareU.S. charges Russian for phishing 80,000 freelancers via 255 fake accounts and Excel macros delivering TVRAT and DarkVNC for remote access and data theft.
MalwareCrowdStrike and law enforcement disrupted the 23-year-old Sality P2P botnet, sinkholing bots and blocking payloads used for crypto theft via EggJagger.
APTIran's Nimbus Manticore lures developers with fake LinkedIn coding tests to deploy NodeRabbit and PollCat RATs for cross-platform espionage.
RansomwareBerlin confirmed data theft from two ministries in a cyberattack and refused to pay ransom. Rhysida claims 5.79TB stolen, unverified by officials.
MalwareMicrosoft's TerminalFix uses fake CAPTCHAs and PowerShell to deliver steganographic malware, creating encrypted tunnels into corporate networks.
MalwareValleyRAT backdoor spreads via trojanized QN Wallpaper installer using DLL sideloading to disable Windows Defender and gain full remote control.
RansomwareAurora ransomware used Cursor with Claude Sonnet for attacks on 20+ orgs. Zig encryptor for Windows, Linux, ESXi. Details inside.
APTSygnia uncovers Fire Ant's cyber-espionage expanding to Cisco IOS XR routers, TACACS servers, and Linux hosts using invisible tunnels and credential theft.
MalwareDiscover how TerminalFix malware uses fake Cloudflare CAPTCHAs to trick users into installing a reverse-tunnel backdoor via Windows Terminal, posing a serious threat to organizations.
MalwareDiscover how 19 malicious modules in Chrome and Edge extensions steal crypto, seed phrases, and sessions. Learn immediate steps to secure your accounts.