Leaked university records have opened an unusual window into Russia’s military cyber ecosystem. The documents point to a structured training program, not a newly discovered piece of malware, that appears to feed people into GRU units associated with APT28 and Sandworm.
The finding matters because these groups have been linked to espionage, credential theft, sabotage, and disruptive operations against governments and vital services.
Their documented approaches include phishing, stolen credentials, and the exploitation of exposed systems, so the leak has relevance far beyond Russia.
Analysts at DomainTools Investigations examined the material and found a program joining classroom instruction, attacker-versus-defender exercises, and supervised military placements. It offers rare detail on the human pipeline behind enduring campaigns.
DomainTools Investigations said in a report shared with Cyber Security News (CSN) that the records do not identify a new victim campaign or a fresh implant.
Instead, they outline how technical skills, operational planning, and intelligence work may be developed together, helping explain the persistence and range of Russian military-linked cyber activity.
The leaked archive concerns Department No. 4 within Bauman Moscow State Technical University’s Military Training Center. It contains personnel lists, schedules, examinations, and placement records documenting how trainees were recruited, assessed, and assigned.
Researchers assessed the files as authentic institutional material after reviewing their internal consistency and metadata. The archive reportedly includes about 1,600 files and shows roughly 250 career and reserve students.
Three specialties formed the program’s core: Special Intelligence Service, information-technical effects and protection, and information-technology protection. The information-effects stream was the largest, with about 120 students in 2024, suggesting a broad workforce model.
The documents link graduate placements to Military Unit 26165, associated with APT28, Fancy Bear, and Forest Blizzard, and Military Unit 74455, associated with Sandworm.
The difference matters: APT28 is commonly tied to intelligence collection, while Sandworm has been linked to disruption and destruction, including Russian sabotage attacks on infrastructure.
Former Unit 26165 commander Viktor Netyksho appears in the training and evaluation structure, and correspondence bears senior GRU officer Yuriy Shikolenko’s signature. Still, the records do not prove every named student carried out an intrusion.
Daniil Porshin and Aleksey Kondrashov, reportedly assigned to Units 26165 and 74455 after graduating in 2024, are not publicly tied to specific operations.
The coursework covered password attacks, server exploitation, vulnerability research, malware creation, penetration testing, technical surveillance, propaganda, and information manipulation. It also included cryptography, code analysis, intrusion detection, and hardware inspection.
A 2023 conference volume included malware triage, infrastructure mapping, anomaly detection, system-call monitoring, and attacker-versus-defender simulations, reflecting skills used to reconstruct an intrusion.
The curriculum shows that trainees were expected to understand both offensive activity and the defensive response to it.
One paper examined a phishing operation built around self-extracting archives and renamed UltraVNC binaries. This resembles social engineering seen in weaponized Office document campaigns, where trusted-looking files or messages open a route to compromise.
Field placements then moved the training beyond theory. Special-intelligence students went to Kursk, Bataysk, Sevastopol, and Bugry; the information-effects group was mainly sent to Moscow, Mosrentgen, and Voronezh; and information-protection trainees were placed at the Krasnodar Higher Military School.
The leak also describes a financial-systems security path within the special-intelligence stream. Training in payment infrastructure, transaction systems, identity controls, fraud detection, and sensitive-data protection could support defensive duties, but could also help personnel assess weak points in banks, processors, or government revenue systems.
For organizations, the practical response is to build durable defenses rather than chase a presumed new indicator set.
Patch internet-facing systems, restrict remote access, use phishing-resistant multifactor authentication, separate critical technology from office networks, and monitor unusual logins and device activity.
This is timely as APT28 abuses edge routers and Sandworm shifts toward industrial systems. The central conclusion is institutional: Department No. 4 appears to generate operators, analysts, planners, defenders, and reserve personnel for several parts of Russia’s General Staff. The archive’s acquisition route remains unknown for security teams worldwide.
| Type | Indicator | Description |
|---|---|---|
| File name | 00000253_ГЗ 2_1 Информационно-техническое оружие.ppt | PowerPoint file referenced in the leaked curriculum material on information-technical weapons |
| File name | МК- Гибкость итог-1.pdf | PDF file referenced in Bauman administrative records connected to the reported identity change of Ivan Makarov / Mark Fisher |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Prevent incidents due to slow investigations. Power your Tier 1 with threat intelligence from 15K SOCs: Integrate TI Lookup in your SOC
Dark Caracal has returned with a new tool that helps attackers stay connected when defenders…
Claude Code Opus 5 in Auto Mode can be tricked into running malicious code via…
The U.S. Cybersecurity and Infrastructure Security Agency has added a Linux kernel vulnerability, tracked as…
Cybercriminals have stolen the personal data of about 8.7 million customers following a cyberattack on…
More than 100 technology, cybersecurity, and financial-services organizations have joined OpenAI in an open letter…
Threat actors are increasingly abusing overlooked Active Directory service principal name (SPN) misconfigurations to launch…