Leaked Bauman University Records Reveal Russian Military Cyber Training Pipeline

Summary
DomainTools analyzes leaked Bauman University records, saying Department No. 4 trained roughly 250 students in military intelligence, cyber effects and information protection, with reported links to GRU units associated with APT28 and Sandworm.
Key points
- DomainTools says it examined about 1,600 leaked files and found metadata and internal records consistent with Bauman University origins; the method of access and exfiltration remains unknown.
- The records describe roughly 250 career and reserve students across three specialties: special intelligence, information-technical effects and protection, and information-technology protection.
- Coursework reportedly covered password attacks, server exploitation, malware, penetration testing, intrusion detection, cryptography, and hardware inspection.
- The report describes attacker-versus-defender exercises, malware analysis, and practical placements at military units and academies.
- Consortium reporting and the leaked records reportedly link graduates to GRU Units 26165 and 74455, associated respectively with APT28 and Sandworm; the article does not establish that named graduates took part in specific operations.
- A paper in the collection analyzed a phishing campaign using self-extracting archives and renamed UltraVNC binaries, but the report says its attribution claims had limited support.
- A DarkForums account using the name “Losyash” distributed links to the data; its role in obtaining or first publishing the files is unconfirmed.
Article Details
- Attack Vectors
- Department No. 4 coursework covered password attacks, server exploitation, software vulnerabilities, malware creation, and penetration testing.
- A paper analyzed a campaign using phishing and self-extracting archives, in which operators deployed renamed UltraVNC binaries and manually controlled infrastructure.
- Coursework included reconstructing cyberattack chains, analyzing scripts, and mapping command infrastructure.
- Defensive Notes
- Training covered intrusion detection, malware triage, code analysis, cryptography, and steganography.
- Students studied detecting and blocking adversary activity, technical deception, counterattack, and protecting information and military systems.
- Technical protection instruction included hardware inspection and identifying physical implants and undocumented device functions.
MITRE ATT&CK
People
Aleksey Stanislavovich KondrashovReported Department No. 4 graduate assigned to Military Unit 74455; the article says no public attribution links him personally to a Sandworm campaign.Daniil Alekseyevich PorshinReported Department No. 4 graduate assigned to Military Unit 26165; the article says no public evidence links him to a named cyber operation.Ivan MakarovEnrolled in a Department No. 4 track described as counterintelligence-related; the article reports he changed his name to Mark Fisher in 2023.Kirill StupakovReported GRU officer and Department No. 4 educational director and deputy head; designed curriculum components and managed the department's relationship with military intelligence.Mark FisherName adopted by Ivan Makarov in 2023, according to the article; no public evidence establishes a foreign assignment or illegal intelligence cover.Viktor NetykshoFormer commander of Military Unit 26165; department records place him in its teaching, evaluation, and oversight structure. The United States indicted him over alleged operations against U.S. political organizations.Vladislav Yevgenyevich BorovkovBauman graduate and GRU officer reportedly assigned to Military Unit 29155; charged by the United States in 2024 over alleged cyber operations, though the leak does not conclusively establish Department No. 4 graduation.Yuriy ShikolenkoIdentified by the United Kingdom as a senior GRU officer; leaked correspondence shows his signature on student-evaluation documents, though his exact role is not established.
Threat Actors
APT28Associated in the article with GRU Military Unit 26165.Fancy BearThe article identifies Fancy Bear as another tracking name for APT28.Military Unit 29155The article describes a cyber component within the unit as conducting destructive operations and reports allegations of operations against Ukraine and organizations in NATO countries.SandwormAssociated in the article with GRU Military Unit 74455 and described as conducting disruptive and destructive cyber operations.
Malware
Tools
Countries
RussiaThe scale indicates that Russia was not training only a small cadre of elite intrusion specialists. It was producing a wider workforce capable of integrating cyber operations into military planning.Ukrainemapped the command infrastructure. The paper offered limited support for its attribution theory (e.g. Ukraine), but its methodology still demonstrated practical training in malware analysis and open sourceUnited Statesdepartment’s teaching and oversight structure. Netyksho was among the GRU officers indicted by the United States for operations connected to the theft and release of material during the 2016 U.S. presidential
Industries
Defenseинформационных технологий”). The curriculum combined both offensive and defensive techniques for cyber defense, as well as offensive doctrine for active measures campaigns and GRU activities. Field placements thenFinancial sectorService. The program focused on the security of automated systems used in the credit and financial sector. This suggests that students entered the military intelligence track with prior technical knowledge