Illustrative image generated with AI
Bauman: Leaked Documents Expose the University Pipeline for GRU Cyber Operators
Over 2,000 leaked Bauman University files expose Department No. 4 training GRU cyber operators linked to APT28 and Sandworm operations.
Text generated by artificial intelligence, published without human review. AI transparency
More than 2,000 internal documents from Bauman Moscow State Technical University describe a structured pathway for training personnel destined for Russian military intelligence and cyber operations. At the center of the investigation, published on September 3, 2026, is Department No. 4—a structure absent from the university’s public organizational chart but operating within its Military Training Center.
Also known as “Special Training,” the department reportedly trained approximately 250 career personnel and reservists over six academic years. An estimated 10 to 15 students per year were allegedly selected, before completing their studies, for assignments linked to the GRU, Russia’s military intelligence service.
The files make it possible to reconstruct not only the courses, but also the assessment, supervision, and assignment processes. Some graduates appear to have been linked to units associated with APT28 and Sandworm/APT44, two of the Russian threat groups most closely monitored by the international security community.
More Than 2,000 Files Reveal a Non-Public Structure
The documentation includes academic and administrative records through 2025. It was reviewed by a consortium comprising The Insider, The Guardian, Le Monde, Der Spiegel, Delfi, VSquare, and FRONTSTORY.PL, while DomainTools conducted an independent analysis of the files.
The data may have been published on DarkForums by a user identified as “Losyash.” However, it has not been established whether the account directly stole the documents or obtained them from another source.
The value of the leak lies in the granularity of the information. The files show an institutional mechanism that begins at the university, continues through specialized technical and military training, and culminates in assignments to Russian General Staff structures.
Department No. 4 reportedly operated without appearing in the university’s public organizational structure. This fact, together with the “Special Training” designation, points to an organizational separation from standard academic programs while preserving access to Bauman’s scientific and engineering expertise.
The structure allegedly trained approximately 250 people in three military specializations: special intelligence; the use and countering of technical-information influence capabilities; and information technology protection. This was therefore not a conventional university cybersecurity program.
A Curriculum Combining Offense, Defense, and Intelligence
The subjects reconstructed from the documents cover the full lifecycle of a military cyber operation. They include espionage, offensive operations, electronic reconnaissance, systems protection, cryptography, steganography, code analysis, and intrusion detection.
Part of the program focused on malware analysis and cyber threat intelligence. This detail is significant because it indicates preparation for operators capable not only of developing or deploying offensive tools, but also of studying adversaries’ techniques, infrastructure, and behavior.
The training also extended to the hardware layer and the supply chain. Topics included:
- hardware inspection and the detection of physical implants;
- firmware and embedded-systems analysis;
- identifying undocumented functionality in devices;
- testing and protecting specialized military platforms;
- supply-chain security and procurement;
- protecting systems designed to process sensitive information.
Red team and blue team activities were not organized as separate tracks. Offensive and defensive capabilities were treated as components of the same discipline, with the aim of preparing personnel who could understand both operational perspectives.
This approach helps explain the nature of the program. Operators were not trained for a single technical function, but to move between intrusion, protection, analysis, and intelligence support. It was a multidisciplinary preparation designed for a range of assignments within the military apparatus.
Propaganda Enters Academic Exercises
The concept of cyber warfare adopted by Department No. 4 did not stop at compromising networks and devices. The documents also include practical information-influence activities.
In one exercise, students were required to produce a social media video using techniques described in the teaching materials as manipulation, pressure, and covert propaganda. The assignment was recognized as part of their academic training.
The courses defined “technical-information weapons” broadly as tools and methods capable of altering, copying, blocking, destroying, or manipulating information. Within this framework, malware, a reconnaissance capability, and a propaganda product can occupy the same operational space.
The program therefore draws a less distinct boundary than is common in Western practice between network security, electronic warfare, and influence operations. These capabilities are integrated to support campaigns in which intelligence collection, technical intrusion, and perception management may serve shared objectives.
For defenders, this model suggests that every activity should not automatically be analyzed as an isolated incident. An espionage campaign may prepare a destructive action or support an influence operation, and the different phases may not be handled by the same individuals.
Links to APT28, Sandworm, and Military Unit 29155
One of the most significant names to emerge from the files is Viktor Netyksho, a Major General and former commander of Military Unit 26165. This GRU unit is publicly associated with APT28, also known as Fancy Bear, Sofacy, and STRONTIUM.
Netyksho was among the 12 GRU officers indicted by the United States in 2018 over interference in the 2016 presidential election. The documentation places him within the teaching and supervision structure of Department No. 4 and refers to his previous role at the 85th Main Special Service Center.
The documents also indicate graduate assignments to three units:
- Military Unit 26165, associated with APT28;
- Military Unit 74455, associated with Sandworm or APT44;
- Military Unit 29155, linked to sabotage and assassination operations in Europe.
Military Unit 74455, known as the Main Center for Special Technologies, has been associated with the 2017 NotPetya attack and other destructive operations against Ukraine. One graduate listed in the records is Aleksei Kondrashov, who reportedly completed the Department No. 4 program in 2024 and appears to be linked to Unit 74455.
The documentary connection does not, however, prove that Kondrashov participated in NotPetya or any other specific activity. The same limitation applies to every person identified in the records: an administrative assignment, supervisory relationship, or affiliation with a unit does not by itself establish individual responsibility for an attack.
Implications for Attributing Russian Operations
The discovery does not identify a new vulnerability, previously unknown malware, or command-and-control infrastructure. Instead, it reconstructs the system through which some operators are identified, trained, and directed toward GRU structures.
For threat intelligence teams, the documents provide organizational context. They make it possible to connect university programs, military supervisors, technical specializations, and subsequent assignments, revealing a stable pipeline rather than a series of ad hoc recruitments.
The presence within the same program of capabilities associated with APT28 and Sandworm also supports a more integrated view of Russian activity. Espionage, digital sabotage, military reconnaissance, technical surveillance, and influence operations may share doctrine, training, and recruitment channels.
No technical indicators of compromise—such as IP addresses, domains, hashes, or malware samples—have been published. As a result, the files do not directly provide detection rules or mitigations.
Organizations can nevertheless adapt their analytical approach. Monitoring should correlate military units, individuals, roles, training backgrounds, and threat groups while maintaining a strict distinction between contextual indicators and technical evidence. Attributing an incident requires telemetry, infrastructure, malware, tradecraft, and other verifiable elements.
The documents clarify how personnel may reach these units. They do not automatically show what each graduate did after being assigned.
Sources
This article is an original reworking based on the sources below.
