Threat Intelligence Report: University Leak Exposes Russia’s Military Cyber Training Pipeline

Published on: 
August 26, 2026

Executive Summary

Recently leaked records show that Bauman Moscow State Technical University’s Department No. 4 operated as a long-term training pipeline for Russian military intelligence and cyber operations. The department served several elements of the Russian General Staff and trained roughly 250 career and reserve students across three specialties: special intelligence (“Служба специальной разведки”), operational information-technical effects (“Применение сил и средств информационно-технического воздействия и защиты от информационно-технического воздействия”), and information-technology protection (”3ащита информационных технологий”). The curriculum combined both offensive and defensive techniques for cyber defense, as well as offensive doctrine for active measures campaigns and GRU activities. Field placements then moved students from classroom instruction into military units and academies aligned with their specialties, giving them supervised exposure to intelligence operations and preparing them for military and government operations careers.

Bauman Staff and Graduates Dept 4

Reporting identified graduates assigned to GRU Military Unit 26165 (associated with APT28) and Military Unit 74455 (associated with Sandworm), and linked senior officers, including former Unit 26165 commander Viktor Netyksho, to student oversight. A DarkForums account named “Losyash” may have helped distribute the leaked material, although its role in obtaining or first publishing the records remains unconfirmed. 

The department focuses on cyber warfare activities and defense, as well as UAV and communications operations and technologies. The leak reveals a repeatable institutional system for producing Russian military cyber operators, analysts, planners, defenders, and reserve personnel. 

The Bauman Leak

The documents, which have been examined by an international consortium of media outlets that included The Insider, The Guardian, Le Monde, Der Spiegel, Delfi, and VSquare, describe a concealed unit known as Department No. 4 (Кафедра № 4) inside Bauman’s Military Training Center. Published investigations connected the department to the Main Directorate of the Russian General Staff, commonly known as the GRU, and identified graduates assigned to military units associated with APT28 and Sandworm.

DTI reviewed the full leaked evidence separately circulated through ‘DarkForums RU’ on the darknet, a cybercrime forum used to advertise and distribute stolen databases, compromised accounts, malware, and other illicit material. DarkForums emerged as a prominent competitor to the RaidForums and BreachForums ecosystem and experienced substantial growth after the disruption of BreachForums in 2025. (S2W

A DarkForums profile associated with the handle ‘Losyash’ provided the leak’s distribution. The account was created on June 25, 2026, and had recorded only one thread and one post when the profile was investigated. The account had accumulated four hours and twenty-seven minutes of forum activity and was last recorded as visiting the site on July 10, 2026, at 7:09 p.m.


The profile contained no biography, location, homepage, gender, reputation history, or prior username changes. It had referred no other members and had received no forum awards. This is consistent with a narrowly used or recently created account rather than an established DarkForums persona. The sole post only stated they had Russian military data for download and presented two links online to download the 1.8gb of data.

The internal consistency of the Bauman leak files, their personnel structures, curricula, military specialty codes, approval chains, internship records, and subsequent corroboration by journalists support the assessment that the collection contains authentic institutional material. The available evidence does not yet identify how the files were obtained; however, our assessment of the data itself as well as all of its attendant metadata, shows that the files do belong to Bauman University. The metadata investigation shows the actual systems, users, folder hierarchies, and other data linking individuals as well as infrastructure that the data came from.

FOCA Metadata Analysis servers connected to files

FOCA metadata analysis of users from files

Using tools such as FOCA, analysis was carried out on all of the 1600 files ranging from Word files, PowerPoint slide decks, PDF files, Excel spreadsheets, images, and .ics (calendaring/email) systems showing a full range of meetings and presentations carried out during the claimed leaks timeframe. The metadata analysis corroborates the assessment that the files originated within Bauman University’s administrative and technical environment.

While the files show many users and other data that lend credence to the veracity of their provenance, investigation of them has yet to determine exactly what accounts might have been compromised to access these and to exfiltrate them from the university systems. However, this evidence does lead investigators to believe that this is not an effort to false intelligence on Russian operations.

The Contents of the Leak

The Bauman leak is a broad institutional archive rather than a single operational dossier. It includes personnel rosters, course schedules, examinations, attendance and fitness records, and medical screening files. It also includes force-planning tables, curriculum material, conference papers, and administrative correspondence. Together, the files show how Department No. 4 recruited, trained, evaluated, and placed career and reserve students across three specialties: VUS 093400 Special Intelligence Service, VUS 141600 information-technical effects, and VUS 751100 information-technology protection.The records reveal a stable population of roughly 250 students across all six university years, with 86 new trainees planned for 2024 and a substantial reserve component. Internship records place students at military units and academies in Moscow, Mosrentgen, Voronezh, Kursk, Bataysk, Sevastopol, Bugry, and Krasnodar.

Sampling of files from leak

Image files from leak of classes and graduates

The collection also includes malware-analysis and cyber threat intelligence research, manpower-planning documents, and a financial-sector cybersecurity specialization feeding into VUS 093400 (SIS). It further connects Bauman to Russian military research institutes, academies, and operational structures. Although the analyzed files do not provide every final graduate assignment, they expose the personnel, training, doctrine, and administrative system behind a durable Russian military cyber and technical-intelligence pipeline.

The Department No.4 Program

The files show that the Bauman University Department No. 4 was substantially broader than the shorthand description of a “GRU hacker school” purported in public reporting. It functioned as a force-generation institution serving several components of the Russian General Staff. Internal material states that the department prepared officers for the Main Directorate, the Main Operational Directorate, and the 8th Directorate, organizations associated with military intelligence, operational planning, classified communications, cryptography, and information protection (e.g. blue team functions including cryptographic systems, hardware, etc).

Bauman University Dept 4 Flow Diagram for Placement and Curricula


Students were divided among three numbered training groups, each aligned to a separate military occupational specialty and General Staff requirement. 

Group No. 1, VUS 093400, was formally designated “Special Intelligence Service (SIS)” and operated under qualification requirements approved by the head of the Main Directorate of the General Staff. 

Group No. 2, VUS 141600, was designated “Employment of Forces and Means for Information-Technical Effects and Protection Against Information-Technical Effects (EFMIT)”. This group trained personnel for operational cyber effects and defensive information-technical activity under requirements approved by the Main Operational Directorate. 

Group No. 3, VUS 751100, was designated “Protection of Information Technologies” and appears to have prepared officers for secure military systems, classified information protection, communications security, or related technical-security functions.

Public reporting has concentrated on VUS 093400 (SIS) because it provides the clearest link to military intelligence. The leaked records indicate, however, that VUS 141600 (EFMIT) was the department’s largest program. Approximately 120 career and reserve students were enrolled in that stream during 2024, close to half of the department’s total population. VUS 141600 is Department No. 4’s operational cyber-warfare specialty, training officers to plan and employ information-technical effects and to defend military systems against equivalent adversary operations. (*note: this training for both blue team and red team planning and function is a feature of Russian military doctrine) 

The scale indicates that Russia was not training only a small cadre of elite intrusion specialists. It was producing a wider workforce capable of integrating cyber operations into military planning.

GRU Cyberwarfare Curriculum

A Department No. 4 lecture described information-technical weapons as capabilities used to alter, destroy, copy, block, or steal information. The curriculum combines offensive intrusion, defensive security, technical intelligence, and psychological operations. Students received instruction in password attacks, server exploitation, software vulnerabilities, malware creation, penetration testing, technical surveillance, propaganda, and information manipulation.

00000253_ГЗ 2_1 Информационно-техническое оружие.ppt | Machine Translation: “GZ 2/1 Information-Technical Weapons”

Machine Translation: “Information-technical weapons are a collection of specially organized information, information technologies, methods, and means that make it possible to purposefully alter, destroy, distort, copy, or block information; overcome protection systems; restrict access by legitimate users; conduct disinformation; disrupt information-processing systems; and disorganize technical systems, computer systems, networks, and other high-technology infrastructure.”

The instructional material did not sharply separate offensive and defensive cyber operations. The inclusion of both offensive and defensive instruction trains operators to attack and defend all in one.  Defensive measures included detection, blocking, concealment, diversion, technical deception, counterattack, and activity against adversary infrastructure intended to disrupt an ongoing operation.


Technical protection training covered cryptography and steganography, as well as code analysis and intrusion detection. Students were also trained in hardware inspection, the discovery of physical implants, and the identification of undocumented device functions. These subjects point to possible assignments in technical counterintelligence and supply chain security, as well as firmware analysis and embedded system inspection. Other likely functions include secure procurement and the protection of specialized military platforms.

The files also reveal an underreported malware-analysis and cyber threat intelligence program. A 2023 Bauman Military Training Center conference volume; “Current Issues Concerning the State and Prospects for the Development of Weapons, Military, and Special Equipment of the Aerospace Forces” (Актуальные вопросы состояния и перспектив развития вооружения, военной и специальной техники Воздушно-космических сил) contained research on malware triage, infrastructure mapping, anomaly detection, system-call monitoring, and attacker versus defender exercises.

Page 74 of tabletop exercise

Analysis of the Operational Methodology of a Pro-Ukrainian APT Group in Conducting Cyberattacks (Анализ методики работы проукраинской APT-группировки при реализации кибератак)

One paper in particular; ”Analysis of the Operational Methodology of a Pro-Ukrainian APT Group in Conducting Cyberattacks” (Анализ методики работы проукраинской APT-группировки при реализации кибератак), examined a campaign built around phishing and self extracting archives. In the campaign, the operators deployed renamed UltraVNC binaries and manually controlled infrastructure. They also reconstructed the execution chain, extracted configuration parameters, and mapped the command infrastructure. The paper offered limited support for its attribution theory (e.g. Ukraine), but its methodology still demonstrated practical training in malware analysis and open source intelligence collection. It also showed campaign clustering and script deobfuscation, with the authors reconstructing the intrusion from available evidence and reporting by others.

GRU Cyberwarfare Coursework

Department No. 4 combined classroom instruction with controlled attacker versus defender exercises. Students selected tactics and responded to opposing actions, assessing the effectiveness of each strategy. Related coursework covered intrusion detection and malware triage, including script analysis and remote access tooling. Students also studied infrastructure mapping and technical deception and learned to reconstruct cyberattack chains.

Based on this information, the program extended beyond theoretical cybersecurity instruction. It included cyber range training and adversary emulation, as well as incorporating incident response and operational planning. Students were expected to understand how attackers find and exploit weaknesses. They were also trained to prioritize limited defensive resources and place cyber activity within wider military operations.

Practical placements connected the coursework to military units and academies aligned with each specialty:  

Group No. 1 trained under VUS 093400 for the Special Intelligence Service. Its trainees were sent to Kursk and Bataysk, with other placements including Sevastopol and Bugry. The distribution of these assignments points to exposure to intelligence units and collection functions. It also suggests contact with specialized military formations and operational environments supporting the Main Directorate of the General Staff. These placements likely gave students opportunities to apply intelligence tradecraft and network analysis. They may also have practiced technical collection and cyber enabled reconnaissance under the supervision of active military personnel.

Group No. 2 trained under VUS 141600 for information technical effects and protection against those effects. Students were primarily placed in Moscow and Mosrentgen, with others sent to Voronezh. These locations appear to be tied to military command and planning but also support communications and operational activity. The placements likely exposed students to the use of offensive and defensive cyber effects within headquarters functions. They may also have supported work involving automated command systems and information operations.

VUS 141600 was the department’s largest program. It appears designed to produce personnel who could support cyber operations at scale, extending beyond individual network intrusion.

Group No. 3 trained under VUS 751100 for the protection of information technologies. Its trainees were sent to the Krasnodar Higher Military School, which is associated with military communications and information security. It also supports the protection of command and control systems. This placement likely focused on secure networks and classified information protection.

Taken together, the placement pattern suggests that each numbered group followed a distinct operational pathway: 

VUS 093400 supported military intelligence and special intelligence functions. 

VUS 141600 supported cyber effects, defensive operations, and command-level integration. 

VUS 751100 supported secure communications and information protection. 

The combination of technical coursework, adversary-emulation exercises, and field placements created a structured progression from academic instruction to supervised military application, preparing graduates for assignments across Russia’s intelligence, cyber operations, command, and technical-security organizations.

The Personnel Pipeline

The consortium’s reporting identified graduates who entered two named GRU cyber formations. Military Unit 26165 is the 85th Main Special Service Center of the GRU, commonly associated with APT28, also tracked as Fancy Bear, Forest Blizzard, and several other vendor designations. The unit conducts military intelligence collection, cyber espionage, influence-support operations, and intrusions against government and strategic targets. 

Military Unit 74455 is the GRU’s Main Center for Special Technologies, the organization associated with Sandworm, also tracked as APT44. Its function centers on disruptive and destructive cyber operations, including attacks against critical infrastructure, military targets, government networks, and operational technology.


The data also connected senior GRU officers to the supervision and evaluation of Bauman students. Viktor Netyksho, the former commander of Unit 26165 and the 85th Main Special Service Center, is part of the department’s teaching and oversight structure. Netyksho was among the GRU officers indicted by the United States for operations connected to the theft and release of material during the 2016 U.S. presidential election. The presence of officers from Unit 26165, together with graduate placements into Units 26165 and 74455, links Department No. 4 directly to both the GRU’s espionage-focused cyber apparatus and its destructive operational arm.

GRU Financial Systems Protection and Adversarial Programs

The records identify a specialized academic pathway that connected financial-sector cybersecurity training directly to Group No. 1, VUS 093400, Special Intelligence Service. The program focused on the security of automated systems used in the credit and financial sector. This suggests that students entered the military intelligence track with prior technical knowledge of banking platforms, payment infrastructure, transaction-processing systems, identity controls, fraud detection, and the protection of sensitive financial data.

The available material does not define the operational purpose of this specialization or identify the units that ultimately received its graduates. Its placement under the Special Intelligence Service, however, indicates that the training was likely intended for more than conventional compliance or civilian banking security. The pathway could have prepared personnel to collect intelligence on foreign financial networks, assess the resilience of payment systems, analyze transaction flows, or identify dependencies within banking and economic infrastructure.

Specialization: Безопасность автоматизированных систем в кредитно-финансовой сфере (специального назначения) | “Security of Automated Systems in the Credit and Financial Sector, Special Purpose”

SIS Automated Systems and Credit and Financial Special Purpose Track

A defensive mission is also plausible. Graduates may have been assigned to protect military financial systems, salary and procurement platforms, defense-industrial payment networks, or other automated systems used to fund and sustain Russian military activity. Such responsibilities would require expertise in access control, cryptography, database security, fraud monitoring, incident response, and the continuity of financial operations during conflict or sanctions pressure.

However, the same knowledge would have clear offensive or adversarial value. Personnel familiar with financial-system architecture could support reconnaissance against foreign banks, payment processors, clearing systems, cryptocurrency services, or government revenue platforms. They could identify weak authentication mechanisms, exposed applications, third-party dependencies, and operational choke points that might be exploited for espionage, disruption, manipulation, or theft.

The pathway may also have supported broader economic intelligence missions. Financial data can reveal procurement activity, defense spending, sanctions exposure, supply-chain relationships, and the movement of funds between governments, contractors, and strategic industries. Access to such systems could provide insight into military readiness, covert financing, industrial capacity, and foreign policy priorities.

This specialization therefore appears to bridge financial cybersecurity and military intelligence. It may have produced personnel capable of protecting Russian financial and military-support systems while also assessing or targeting the economic infrastructure of foreign states. The precise mission remains an intelligence gap, but its inclusion within VUS 093400 indicates that financial systems were treated as an operational intelligence and national-security domain rather than a civilian cybersecurity concern.

Operators Teaching Directly Linked to Russian Intelligence Services

The analysis of the Bauman files identify several individuals with direct or strongly documented connections to the Main Directorate of the Russian General Staff, commonly known as the GRU. No comparably substantiated direct personnel links to the Federal Security Service (FSB) or the Foreign Intelligence Service (SVR), were identified in the material reviewed to date. References to domestic security, counterintelligence, surveillance, or foreign intelligence functions should therefore not be treated as proof of FSB or SVR affiliation. The documented personnel network is overwhelmingly GRU-centered.

*Note* The dump also has a full listing of professors and graduates for this period and their GRU placements (MOS) which may be of interest for others in the IC. We have not listed them all here but the documents are available.

Personnel Dossiers

Lieutenant Colonel Kirill Stupakov

Kirill Stupakov was the educational director and deputy head of Department No. 4. Consortium reporting identifies him as a GRU officer who designed parts of the curriculum and managed the department’s relationship with military intelligence. Leaked instructional material attributed to his program covered cyber operations as well as technical surveillance and information warfare. His position placed him between Bauman’s academic administration and the GRU organizations responsible for directing training requirements and receiving graduates. 

Stupakov’s résumé reportedly states that he commanded a GRU unit for three years and remained in that position until July 11, 2025. The files also show him preparing evaluations and correspondence for senior GRU officers, indicating that his duties extended beyond classroom teaching. He appears to have managed personnel reporting and student assessment while ensuring that Department No. 4 produced graduates who met operational requirements. 

Major General Viktor Borisovich Netyksho

Viktor Netyksho is a senior GRU officer and former commander of Military Unit 26165. The unit is the GRU’s 85th Main Special Service Center and is publicly associated with APT28 and Fancy Bear. Its missions include cyber espionage and credential theft against political and military targets. The United Kingdom identifies Unit 26165 as a long-standing GRU malware-development and intrusion organization.

A Department No. 4 letter dated February 16, 2024 carried Netyksho’s initials and signature. Other correspondence sent departmental staffing and training information to him. These records place him within the program’s evaluation and oversight structure.

The United States indicted Netyksho in July 2018. Prosecutors alleged that he commanded Unit 26165 during operations against U.S. political organizations and the subsequent release of stolen material. The U.S. Treasury designated him in December 2018, and the United Kingdom imposed additional sanctions in July 2025.

Colonel Yuriy Leonidovich Shikolenko

No independently verified public photograph was identified during this research

Yuriy Shikolenko is identified by the United Kingdom as a senior GRU officer. The UK sanctioned him on July 18, 2025 for responsibility for, or support to, malicious cyber activity and his continuing GRU service.

Leaked data shows Shikolenko’s signature on Department No. 4 correspondence concerning student evaluations. The reporting does not establish his exact command position or daily administrative role. His involvement nevertheless shows that senior GRU personnel reviewed the readiness of students expected to enter military intelligence service.

Former Students


Daniil Alekseyevich Porshin

Image of Porshin, born June 26th 2000 from Bauman League Football (Bauman State Tech)

Daniil Porshin attended Bauman University from 2018 through 2024. The leak describes him as one of the strongest students in his cohort and states that he completed Department No. 4 training in subjects that included cryptography and network security as well as offensive techniques such as password attacks and server exploitation.

After graduating in 2024 Porshin was reportedly assigned to GRU Military Unit 26165. No public evidence reviewed links him to a named cyber operation. He should therefore be characterized as a reported unit assignee rather than an established APT28 operator.

Aleksey Stanislavovich Kondrashov

Aleksey Kondrashov graduated from Department No. 4 in 2024 and reportedly received the rank of lieutenant. The leak shows him in his post-graduation assignment with Military Unit 74455. The unit is publicly identified with Sandworm and destructive GRU cyber operations. The UK attributes major disruptive activity to Unit 74455, including operations against Ukrainian telecommunications infrastructure. 

The reviewed public record contains little independent biographical information about Kondrashov. No official indictment or public attribution links him personally to a specific Sandworm campaign.

Ivan Makarov / Mark Fisher

Ivan Makarov was born in Moscow in 2001 and enrolled in a Department No. 4 track described by leaked data as counterintelligence-related. In April 2023 he legally changed his name to Mark Fisher. The change reportedly involved replacement identity documents and was reflected in Bauman’s administrative records (МК- Гибкость итог-1.pdf).

Makarov’s father shared a registered address with Military Unit 26165. Journalists have compared the adoption of a generic Western name with identity-development methods used in previous Russian intelligence cases. 

No public evidence establishes that Fisher received a foreign assignment or operated under an illegal intelligence cover. 

Vladislav Yevgenyevich Borovkov

Vladislav Borovkov is a Bauman University graduate and a GRU officer assigned to Military Unit 29155. The United States charged him and four other GRU officers in September 2024 with conducting cyber operations against Ukraine and organizations in at least 26 NATO countries. The alleged activity included vulnerability scanning and destructive operations associated with the WhisperGate campaign.

Unit 29155 is associated with sabotage and covert action. Western governments have also identified a cyber component within the unit that conducts destructive operations against critical infrastructure and government targets. The United Kingdom sanctioned Unit 29155 as an organization and lists it among the three principal GRU cyber formations.

The leak establishes Borovkov’s attendance at Bauman but does not conclusively demonstrate that he graduated from Department No. 4. His relationship to the department must therefore remain qualified.

Conclusion

The documents show that Department No. 4 is a small part of a larger long-term military training system, not a single hacking unit. The program prepared personnel for espionage and offensive cyber operations within a larger Russian technical university system. Its doctrine treated cyber warfare as more than network intrusion. Students were taught not only adversarial cyber warfare, but also a larger holistic doctrine of cyber war using both defense and attack to be better able to carry out successful campaigns.

Practical exercises trained students to operate as attackers and defenders, reconstruct intrusion chains, analyze malware, and map command infrastructure. Technical courses also covered cryptography, firmware, hardware inspection, physical implants, and secure systems.

The strongest conclusion is institutional. Department No. 4 functions as a military cyber academy producing operators, analysts, planners, defenders, and reserve personnel for several elements of the Russian General Staff (GRU) and give a window into their cyber doctrines and programs.

Related Content

Research
Chinese Malware Delivery Domains Part V

Despite law enforcement arrests targeting the Silver Fox threat group in mid-June 2026, its malware delivery network remains active as a Malware-as-a-Service (MaaS) platform. Affiliates continue to deploy hundreds of new typosquatted domains and exploit major cloud services to distribute an obfuscated Gh0stRAT variant.

Learn More
Research
Intelligence Report: The Zedxion Corporate Nexus for Illicit Iranian Financial Funds Transfer for IRGC Entities.

DomainTools Investigations exposes the Zedxion and Zedcex ecosystem—a layered financial architecture leveraging disposable UK shell companies, persistent digital tokens, and UAE-based trade fronts to facilitate IRGC-linked sanctions evasion and illicit Iranian funds transfers.

Learn More
Research
Threat Intelligence Report: The Pro-Iran Hacktivist Ecosystem 2026

Moving beyond traditional state-centric APT structures, the pro-Iran coalition of jihadist-aligned collectives, nationalist actors, and opportunistic groups coordinates via Telegram to turn low-cost cyber operations into high-impact psychological warfare. While individual actors primarily rely on technically unsophisticated tradecraft like DDoS-for-hire tools, website defacements, and recycled breach data, their strategic strength lies in speed, visibility, and rapid mobilization alongside real-world kinetic events.

Learn More