INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
2,000 Leaked Documents Reveal Russia's GRU Cyber Operations
| 2026-09-03 08:12 CRITICAL MEDIUM DATA BREACH STATE-SPONSORED & ESPIONAGE
Executive Summary
AI-generated
The leaked documents reveal a sophisticated training program at Bauman Moscow State Technical University that has been used to turn engineering students into cyber operators for the Russian military intelligence and cyber operations. The university's Department No. 4, which operated as a long-term pipeline for these programs, was identified by DomainTools in September 2026. This suggests that Russia is using its universities as a means of recruitment and training for its cyber warfare capabilities.
Technical Mitigations AI-generated
I can provide the technical mitigations in bullet points as requested:
* Implement a secure password policy with multi-factor authentication to prevent unauthorized access to sensitive systems and data.
* Conduct regular security audits and penetration testing to identify vulnerabilities and weaknesses in the organization's defenses.
* Use encryption techniques, such as end-to-end encryption or secure messaging apps, to protect sensitive information both in transit and at rest.
* Establish a clear incident response plan to quickly respond to and contain cyber-attacks, including procedures for notifying affected parties and conducting forensic analysis.
* Educate employees on cybersecurity best practices, such as avoiding phishing scams, using strong passwords, and being cautious when clicking on links or downloading attachments from unknown sources.
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected
Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.
fr•••••.pl
AI Podcast (EN) detail_available
detail_listen_ai (EN)
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
APT28APT28
NotPetyaNotPetyaSofacySofacy
Target & Sectors
NORTH_AMERICA
NORTH_AMERICA
educationeducation
Incident Timeline
September 1, 2026
Threat actors used a 2,000 document leak to reveal how Russia's GRU cyber operations recruit engineering students.
September 03, 2026
Russian military intelligence and cyber operations are being trained through a long-term training pipeline at Bauman Moscow State Technical University's Department No. 4, which operates as a hidden department for the GRU (Special Training).
Click on any entity below to view its context and source!
target_region
Russian Federation
2,000 Leaked Documents Reveal How Russia Turns Engineering Students Into GRU Cyber Operators
Pierluigi Paganini
September 03, 2026
general_metric
2,000 Leaked Documents
2,000 Leaked Documents Reveal How Russia Turns Engineering Students Into GRU Cyber Operators
Pierluigi Paganini
September 03, 2026
organisation
Leaked Documents Reveal
2,000 Leaked Documents Reveal How Russia Turns Engineering Students Into GRU Cyber Operators
Pierluigi Paganini
September 03, 2026
organisation
SecurityAffairs
Students were taught not only adversarial cyber warfare, but also a larger holistic doctrine of cyber war using both defense and attack to be better able to carry out successful campaigns.”
Follow me on Twitter:
@securityaffairs
and
Facebook
and
Mastodon
Pierluigi Paganini
(
SecurityAffairs
– hacking, Russia)
organisation
Leaked Documents
Leaked Documents Expose Bauman University’s Hidden Department That Trained Hackers, Propagandists, and Malware Developers for the
GRU
More than 2,000 internal documents from Bauman Moscow State Technical University have been reviewed by an international media consortium, and the picture they describe is not a conventional cybersecurity program.
organisation
Bauman Moscow State Technical University
Leaked Documents Expose Bauman University’s Hidden Department That Trained Hackers, Propagandists, and Malware Developers for the
GRU
More than 2,000 internal documents from Bauman Moscow State Technical University have been reviewed by an international media consortium, and the picture they describe is not a conventional cybersecurity program.
organisation
DomainTools
For defenders, DomainTools summarizes the implication precisely: Russian operations should be tracked as a combined threat in which espionage, destructive attacks, military reconnaissance, technical surveillance, and influence campaigns draw on the same personnel pipelines and the same underlying doctrine.
organisation
Bauman University’s
2,000 leaked files expose Bauman University’s hidden Department No. 4, which trained GRU-linked hackers and propagandists linked to APT28 and Sandworm.
threat_actor
APT28
2,000 leaked files expose Bauman University’s hidden Department No. 4, which trained GRU-linked hackers and propagandists linked to APT28 and Sandworm.
Netyksho was the former commander of Military Unit 26165, the GRU formation publicly associated with
APT28
, also tracked as
Fancy Bear
,
Sofacy
, and
STRONTIUM
.
“
Reporting
identified graduates assigned to
GRU Military Unit 26165
(associated with APT28) and
Military Unit 74455
(associated with Sandworm), and linked senior officers, including former Unit 26165 commander
Viktor Netyksho
, to student oversight.” continues the report.
APT28 and Sandworm are the threat groups that security teams track, attribute, and brief about.
organisation
Sandworm
2,000 leaked files expose Bauman University’s hidden Department No. 4, which trained GRU-linked hackers and propagandists linked to APT28 and Sandworm.
data_breach
2,000 leaked files
2,000 leaked files expose Bauman University’s hidden Department No. 4, which trained GRU-linked hackers and propagandists linked to APT28 and Sandworm.
organisation
Bauman’s Military Training Center
“
Department No. 4, also called “Special Training,” operated inside Bauman’s Military Training Center and doesn’t appear anywhere on the university’s public organizational chart.
organisation
Department No
The leaked records identify Major General Viktor Netyksho as involved in Department No. 4’s oversight.
organisation
Department No. 4
“The documents show that Department No. 4 is a small part of a larger long-term military training system, not a single hacking unit.
organisation
Le Monde
The investigation was carried out by a group of media outlets including The Insider, The Guardian, Le Monde, Der Spiegel, Delfi, VSquare, and FRONTSTORY.PL.
organisation
VSquare
The investigation was carried out by a group of media outlets including The Insider, The Guardian, Le Monde, Der Spiegel, Delfi, VSquare, and FRONTSTORY.PL.
organisation
GRU Military Unit
“
Reporting
identified graduates assigned to
GRU Military Unit 26165
(associated with APT28) and
Military Unit 74455
(associated with Sandworm), and linked senior officers, including former Unit 26165 commander
Viktor Netyksho
, to student oversight.” continues the report.
organisation
GRU
The GRU’s talent pipeline tends not to announce itself.
organisation
DarkForums
A DarkForums user known as “Losyash” may have shared the data, but it has not been confirmed that the account originally obtained the records.
organisation
Main Special Service Center
Viktor Netyksho, the former commander of Unit 26165 and the 85th Main Special Service Center, is part of the department’s teaching and oversight structure.”
organisation
Military Unit
A documented assignment to Military Unit 74455 doesn’t establish that a specific person participated in a specific attack.
2026/09/03
The leaked documents revealed how Russia's GRU cyber operations are trained and organized through a system of institutionalized personnel pipelines.
Click on any entity below to view its context and source!
organisation
Sandworm
[…]
The reporting also linked a 2024 Department No. 4 graduate, Aleksei Kondrashov, to Military Unit 74455, widely known as Sandworm.
threat_actor
APT28
The exposure of Department No. 4 also provides researchers with a clearer lens for understanding how the GRU sustains cyber capacity beyond the familiar APT28 and Sandworm brand names.
organisation
GRU
The exposure of Department No. 4 also provides researchers with a clearer lens for understanding how the GRU sustains cyber capacity beyond the familiar APT28 and Sandworm brand names.
organisation
Department No. 4
The exposure of Department No. 4 also provides researchers with a clearer lens for understanding how the GRU sustains cyber capacity beyond the familiar APT28 and Sandworm brand names.
organisation
Main Operational Directorate
The records describe a force-generation mechanism for several General Staff components, including the GRU, Main Operational Directorate, and 8th Directorate, which is associated with protected communications, cryptography, and information security.
organisation
8th Directorate
The records describe a force-generation mechanism for several General Staff components, including the GRU, Main Operational Directorate, and 8th Directorate, which is associated with protected communications, cryptography, and information security.
Tactical Metrics
Metrics
data_breach
2,000
Leaked Files
Click for context!
2,000 leaked files expose Bauman University’s hidden Department No. 4, which trained GRU-linked hackers and propagandists linked to APT28 and Sandworm.
Intelligence Sources
Schneier on Security
2026-09-01
Leaked Russian Cyber-Operations Training Materials
Schneier on Security
Security Affairs
2026-09-03
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Reset / Delete
Incident Version History
CURRENT VERSION
Last Updated: 2026-09-03T12:01
Comprehensive Tactical Telemetry
Highly Correlated Entities
19x
organisation
Identified Entity
Leaked Documents Reveal
entity
7x
timeline
Temporal Reference
September 03, 2026
date
4x
industry
Targeted Sector
Technology
sector
3x
tactic
Cyber Operation Type
Espionage
tactic
2x
target region
Target Country
Russian Federation
country
2x
source region
Origin Country
Russian Federation
country
2x
general metric
Students
250
students
2x
malware
Malware Payload
NotPetya
tool
Contextual Telemetry
Context Block
10 METRICS
general metric
Leaked Documents
2,000
leaked documents
attribution
Attributing Entity
Bauman Moscow State Technical University
’s Department
authority
general metric
.
4
.
general metric
Gru Officers
12
gru officers
tactic
MITRE ATT&CK Technique
T1588.001 - Malware
technique
source region
Origin Region
EUROPE
region
threat actor
APT Group
APT28
actor
data breach
Leaked Files
2,000
leaked files
general metric
Gru Military Unit
26,165
gru military unit
general metric
Military Unit
74,455
military unit
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.