Bauman University Leak Exposes Russia's GRU Cyber-Operator Pipeline
A roughly 1.8GB leak from a covert department at Bauman Moscow State Technical University details how the GRU recruits, vets, and routes students into units linked to APT28 and Sandworm.
Key Takeaways
- A leaked cache of roughly 1,600 files (~1.8GB) from Bauman Moscow State Technical University's Department No. 4 documents a formal pipeline for training and placing students into GRU cyber units.
- Named graduates were reportedly assigned to Military Unit 26165 (linked to APT28/Fancy Bear) and Military Unit 74455 (linked to Sandworm/APT44), including 2024 graduate Aleksei Kondrashov.
- DomainTools researchers say metadata analysis supports the documents' authenticity, but they have not established how the files were obtained or confirmed every listed graduate's operational role.
- For defenders, the value is in attribution and personnel tracking, not new exploit or TTP disclosure — treat named individuals as leads, not proven operators.
What was leaked
According to a DomainTools Investigations report published August 26, 2026, roughly 1,600 files totalling about 1.8GB surfaced from Department No. 4 ('Кафедра № 4'), a unit inside the Military Training Center at Bauman Moscow State Technical University that does not appear in the university's public organisational structure. The cache includes personnel rosters, course schedules, exam and attendance records, medical screening files, curricula, conference papers, and administrative correspondence.
A formal recruitment-to-deployment pipeline
The documents describe three student groups organised by Russian military-occupational-specialty (VUS) codes:
- VUS 093400 — Special Intelligence Service
- VUS 141600 — Information-Technical Effects and Protection, the largest program at roughly 120 students
- VUS 751100 — Information Technology Protection
Coursework reportedly spanned password attacks, server exploitation, vulnerability research, malware development, penetration testing, technical surveillance, cryptography, code analysis, intrusion detection, and information manipulation — a curriculum that blends offensive tradecraft with propaganda and influence-operations training.
Named units and individuals
DomainTools ties the program to two known GRU formations: Military Unit 26165 (the 85th Main Special Service Center), publicly associated with APT28/Fancy Bear/Forest Blizzard, and Military Unit 74455 (the Main Center for Special Technologies), publicly associated with Sandworm/APT44 — the group behind the 2017 NotPetya attack. Named graduates include Daniil Porshin (assigned to Unit 26165), Aleksei Kondrashov, a 2024 graduate reportedly assigned to Unit 74455, and Vladislav Borovkov (assigned to Unit 29155). Faculty named in the leak include Major General Viktor Netyksho, a former Unit 26165 commander, and Lieutenant Colonel Kirill Stupakov.
What the leak does — and doesn't — establish
As Bruce Schneier notes, the reporting does not establish that every listed graduate participated in named operations; unit assignments are placement records, not proof of individual involvement in specific intrusions. DomainTools is equally direct on provenance: 'the available evidence does not yet identify how the files were obtained,' though metadata analysis is consistent with the documents being genuine.
Why it matters for defenders
The strategic value here isn't a new CVE or malware sample — it's structural. The leak reframes Russian offensive cyber capability as an institutionalised, recurring talent pipeline rather than a handful of freestanding threat groups, with shared recruitment and training feeding espionage, destructive, and influence-operation units alike. For threat-intel teams, that means treating named graduates as attribution leads worth correlating against existing APT28/Sandworm activity clusters — cautiously, given the caveats above — rather than as confirmed operators. It's also a reminder that personnel and organisational leaks, not just malware telemetry, are a legitimate and growing input to nation-state attribution work.
Frequently Asked Questions
What is Department No. 4 at Bauman Moscow State Technical University?
It's a training unit inside the university's Military Training Center, absent from Bauman's public organisational structure, that reportedly prepares students under military-occupational-specialty codes for cyber, intelligence, and information-security roles before they graduate into GRU units.
Does the leak prove that named graduates carried out specific cyberattacks?
No. Both DomainTools and Bruce Schneier's write-up stress that the leaked placement records show which unit a graduate was assigned to, not that the individual participated in any specific operation — treat the names as attribution leads, not confirmed operators.
How does this connect to APT28 and Sandworm?
The leak links Department No. 4 graduates to Military Unit 26165 (publicly tied to APT28/Fancy Bear) and Military Unit 74455 (publicly tied to Sandworm/APT44, the group behind the 2017 NotPetya attack), suggesting both groups draw personnel from the same university-based training program.
Sources
- 1Leaked Russian Cyber-Operations Training Materials — Schneier on Security
- 2Threat Intelligence Report: University Leak Exposes Russia's Military Cyber Training Pipeline — DomainTools Investigations
- 3Leaked University Files Reveal How Russia Trains Hackers for Military Cyber Operations — GBHackers