Inside Russia’s Hidden Cyberwar Pipeline: The Bauman Leak Reveals How Future GRU Operators Are Trained + Video

Listen to this Post

Featured ImageA Leak That Exposes More Than a University

For years, Russian cyber operations have often been discussed through the names of groups such as APT28 and Sandworm. Those names describe the operations the world sees, but they do not necessarily explain where the people behind those operations come from, how they are trained, or how a country continuously replaces and expands its cyber workforce.

A newly analyzed collection of approximately 1,600 leaked files from Bauman Moscow State Technical University offers an unusually detailed look at that hidden infrastructure. According to DomainTools Investigations, the material comes from Department No. 4, a military training department that appears to have functioned as part of a long-term personnel pipeline serving elements of Russia’s General Staff and military intelligence.

DomainTools

The significance of the leak is therefore much larger than the discovery of another Russian cyber-training program. The documents describe a system that appears to move students through recruitment, technical education, adversary simulation, evaluation, military internships and eventual placement into specialized military organizations.

That is the part that should concern cybersecurity defenders.

A cyber operation can disappear. A malware family can be dismantled. An individual operator can be identified and sanctioned. But an institutional training system can continue producing new personnel long after a particular campaign ends.

The Bauman Department at the Center of the Story

Bauman Moscow State Technical University is one of Russia’s major technical universities, and Department No. 4 operated within its Military Training Center. DomainTools says the leaked archive contained personnel rosters, curricula, examinations, attendance records, internship information, presentations, correspondence, planning documents and other administrative material.

DomainTools

The collection reportedly covered roughly 250 career and reserve students across three military specialties. Those specialties included special intelligence, information-technical effects and protection against such effects, and information-technology protection.

This distinction matters because the department was apparently not simply a classroom where students learned cybersecurity.

The documents instead describe a broader military workforce-development structure.

Students could receive training connected to offensive cyber operations, defensive security, technical intelligence, cryptography, malware analysis, penetration testing, intrusion detection, technical surveillance and information operations.

DomainTools

Around 1,600 Files Form an Unusual Intelligence Picture

The leaked collection was not a single secret report.

It was an institutional archive.

DomainTools analyzed approximately 1,600 files spanning Word documents, PowerPoint presentations, PDFs, spreadsheets, images and calendar-related files. Metadata analysis reportedly revealed users, folder structures, systems and other information connecting the documents to Bauman University’s administrative and technical environment.

DomainTools

That type of evidence is important because individual documents can potentially be fabricated or manipulated.

A large collection containing interconnected administrative records, personnel structures, training schedules, approval chains and metadata is much harder to dismiss as an isolated piece of fabricated intelligence.

DomainTools concluded that the material originated from Bauman University, although investigators said they still could not determine precisely how the files were obtained or which accounts may have been compromised during the original intrusion and exfiltration.

DomainTools

The Dark Web Connection

The material was reportedly distributed through the Russian-language DarkForums ecosystem.

DomainTools identified an account using the name “Losyash,” created in June 2026, which posted links to approximately 1.8 GB of Russian military-related data. The account appeared to have very limited activity, with only one thread and one post identified during the investigation.

DomainTools

The identity and precise role of the account holder remain unclear.

That distinction is important.

The available evidence supports the authenticity and provenance of the leaked material, but it does not establish exactly who originally accessed Bauman’s systems, how the data was stolen, or whether the DarkForums account belonged to the original intruder.

In other words, the leak itself and the identity of its original source are two separate intelligence questions.

Three Training Tracks Reveal a Larger Military Strategy

Department No. 4 divided students into three major military occupational pathways.

VUS 093400: Special Intelligence Service

The first track focused on special intelligence. Its requirements were associated with the Main Directorate of the General Staff, commonly known as the GRU.

The curriculum and placement information indicate that this pathway was designed for personnel entering intelligence-related roles, with students receiving training relevant to technical intelligence and other specialized military functions.

DomainTools

VUS 141600: Information-Technical Effects

The second pathway is arguably the most important.

VUS 141600 focused on the employment of forces and means for information-technical effects and protection against those effects.

DomainTools found that approximately 120 career and reserve students were enrolled in this stream during 2024, making it the largest of the three programs.

DomainTools

This suggests that

Instead, it appears to include a larger workforce capable of planning offensive operations, defending military systems, analyzing adversaries and integrating cyber capabilities into broader military planning.

VUS 751100: Information Technology Protection

The third track concentrated on information-technology protection.

Its focus appears to have included secure military systems, classified information protection, communications security and related technical-security functions.

The overall structure therefore resembles a military ecosystem rather than a conventional university cybersecurity program.

Students Were Trained to Attack and Defend

One of the most revealing aspects of the leaked curriculum is the apparent absence of a strict boundary between offensive and defensive cyber operations.

Students were exposed to both sides.

Training reportedly included password attacks, server exploitation, software vulnerabilities, malware creation, penetration testing, intrusion detection, cryptography, steganography, technical surveillance and malware analysis.

DomainTools

That combination has an obvious military logic.

A defender who understands how an adversary compromises a server can potentially build stronger detection mechanisms.

An attacker who understands defensive systems can potentially design operations intended to avoid them.

The documents also describe attacker-versus-defender exercises, cyber-range-style activities, intrusion reconstruction and adversary emulation.

DomainTools

The result is a training philosophy centered on understanding the complete cyber conflict rather than one isolated technical skill.

Cyber Warfare Was Treated as More Than Hacking

The leaked instructional material reportedly defined information-technical weapons broadly, encompassing activities capable of altering, destroying, copying, blocking or manipulating information and disrupting information-processing systems and networks.

DomainTools

This is a significant conceptual difference from the way cybercrime is often discussed in the civilian world.

The objective is not necessarily limited to stealing credentials or deploying malware.

Cyber capabilities can become one component of a broader military operation involving intelligence collection, communications, deception, disruption and psychological effects.

The curriculum reportedly included information manipulation and propaganda alongside technical subjects.

That combination indicates that cyber operations were being taught within a wider information-warfare framework.

Malware Analysis and Cyber Threat Intelligence Were Also Part of the Program

The leak reportedly contains evidence of malware-analysis and cyber threat intelligence research.

One 2023 conference volume included work involving malware triage, infrastructure mapping, anomaly detection, system-call monitoring and attacker-versus-defender exercises.

DomainTools

Another paper analyzed the operational methodology of a pro-Ukrainian APT campaign involving phishing, self-extracting archives, renamed UltraVNC binaries and manually controlled infrastructure.

The researchers reconstructed execution chains, extracted configuration information and mapped command infrastructure.

Regardless of the

That is valuable training for both intelligence analysts and operational cyber teams.

Hardware, Firmware and Physical Security Were Not Ignored

The program also appears to have gone beyond conventional network security.

Training covered hardware inspection, physical implants, undocumented device functions, firmware analysis and technical protection.

That opens another dimension of military cybersecurity.

Modern military systems depend on embedded computers, communications equipment, sensors, specialized hardware and supply chains. Protecting those systems requires knowledge of more than operating systems and network traffic.

A technician capable of identifying suspicious firmware behavior or an undocumented hardware component could potentially support counterintelligence, supply-chain security and military platform protection.

The same knowledge can also provide an adversary with insight into how foreign systems are constructed.

The Internship System Connected Education to Military Units

Perhaps the strongest evidence of an institutional pipeline comes from the internship records.

Students were reportedly placed at military units and academies in locations including Moscow, Mosrentgen, Voronezh, Kursk, Bataysk, Sevastopol, Bugry and Krasnodar.

DomainTools

The three training groups followed different placement patterns.

Special-intelligence students were connected to locations associated with intelligence functions.

The information-technical effects group was primarily placed in Moscow and Mosrentgen, with other assignments including Voronezh.

Information-technology protection students were sent to military educational environments associated with communications and information security.

This creates a recognizable progression.

Education → Simulation → Evaluation → Internship → Military Placement

That progression is arguably the most important discovery in the entire leak.

The GRU Connection Becomes Difficult to Ignore

The leaked material reportedly connects graduates to Russian military units associated with major GRU cyber formations.

Military Unit 26165 is associated publicly with APT28, also known as Fancy Bear and Forest Blizzard.

Military Unit 74455 is associated with Sandworm, also known as APT44.

DomainTools and reporting partners identified graduates who were reportedly assigned to these units.

DomainTools

This does not mean every student who passed through Department No. 4 became an APT28 or Sandworm operator.

That would go beyond the evidence.

What the material does show is a personnel connection between a structured military education program and units publicly associated with some of Russia’s most consequential cyber operations.

That is a much more defensible and strategically important conclusion.

APT28 and Sandworm Represent Different Operational Functions

APT28 has long been associated with espionage, intelligence collection and intrusion operations.

Sandworm, meanwhile, has become particularly associated with disruptive and destructive cyber activity, including attacks affecting critical infrastructure and government systems.

The reported placement of graduates into both environments suggests that Department No. 4 was not producing one narrow type of hacker.

It was producing personnel for different missions.

Some could become intelligence specialists.

Others could support offensive cyber operations.

Others could focus on defensive systems, communications or technical protection.

The institution therefore appears capable of feeding multiple parts of a military cyber ecosystem.

Senior GRU Officers Appeared in the Training Structure

The leak becomes even more significant because senior GRU personnel were reportedly involved in student evaluation and oversight.

Among the individuals identified in the DomainTools analysis is Viktor Netyksho, a former commander of Military Unit 26165. Departmental correspondence reportedly carried his initials and signature, placing him within the program’s oversight structure.

DomainTools

Another figure identified in the material is Kirill Stupakov, described as an educational director and deputy head of Department No. 4, with reporting linking him to the GRU.

Yuriy Shikolenko was also identified in connection with departmental correspondence concerning student evaluations.

These connections matter because they suggest the program was not simply teaching military students generic cybersecurity skills.

Operational requirements appear to have influenced the education process itself.

The Financial Sector Adds Another Layer

One particularly interesting element of the leak involves cybersecurity training for automated systems in the credit and financial sector.

The specialization was connected to the special-intelligence pathway.

The exact operational purpose is not established by the available evidence, but the subject matter could have defensive and intelligence applications.

Understanding financial infrastructure can help protect military payment systems, procurement platforms and sensitive financial networks.

It can also provide knowledge relevant to foreign economic intelligence.

Financial networks expose information about procurement, supply chains, sanctions pressure, industrial capacity and government activity.

That makes financial cybersecurity strategically important far beyond conventional banking security.

The People Behind the Pipeline Matter

The leaked archive reportedly contains personnel records and graduate information, providing researchers with an opportunity to map the human infrastructure behind Russian military cyber capabilities.

One reported graduate, Daniil Porshin, attended Bauman from 2018 to 2024 and was described in the leaked material as a strong student who studied subjects including cryptography, network security, password attacks and server exploitation.

He was reportedly assigned to Military Unit 26165 after graduation.

However, DomainTools explicitly notes that there is no public evidence reviewed connecting him personally to a named cyber operation.

DomainTools

That distinction should remain intact.

Being assigned to a military unit associated with an APT group is not the same thing as proving that an individual personally conducted a particular attack.

Another Graduate Was Reportedly Assigned to Unit 74455

Aleksey Kondrashov reportedly graduated from Department No. 4 in 2024 and was assigned to Military Unit 74455.

That unit is publicly associated with Sandworm and destructive Russian cyber operations.

Again, the available evidence does not establish that Kondrashov personally participated in a particular Sandworm campaign.

But the personnel pathway itself is significant.

It demonstrates how an academic military-training environment could feed personnel into an organization already associated with high-impact cyber operations.

The Pipeline Is More Important Than Any Single Name

This is where the story becomes strategically interesting.

The central intelligence value of the leak does not depend on identifying every student.

It comes from the system.

A state-sponsored cyber operation requires people who can develop malware, analyze targets, maintain infrastructure, conduct intelligence collection, plan operations, defend internal networks and interpret the results.

Those skills cannot always be created overnight.

A long-term academic pipeline solves that problem.

It allows the state to identify technically capable students early, provide specialized training, expose them to military environments, evaluate their performance and eventually assign them to operational organizations.

That is a repeatable process.

Why This Changes How Russian Cyber Operations Should Be Understood

The cybersecurity industry often focuses on threat-actor labels.

APT28.

Sandworm.

APT44.

Fancy Bear.

Forest Blizzard.

Those labels are useful for tracking activity, but they can hide the infrastructure beneath the operators.

A group name can disappear.

Personnel move.

Tools change.

Infrastructure is replaced.

But the training pipeline can remain.

The Bauman material therefore suggests that

That is far more difficult to disrupt than a single malware campaign.

What Undercode Say:

The Real Story Is the Human Infrastructure

The most important discovery is not that Russian military personnel are learning offensive cybersecurity.

That should not surprise anyone.

The more important revelation is the apparent institutional mechanism used to produce those personnel.

The documents describe a pipeline rather than a collection of isolated specialists.

Students enter through formal military specialties.

They receive technical education.

They learn offensive and defensive techniques.

They participate in adversary simulations.

They study malware and intrusion chains.

They learn cryptography and technical surveillance.

They can receive exposure to military environments.

Their performance is evaluated.

Senior intelligence personnel reportedly participate in oversight.

Graduates can then move into specialized military units.

That structure creates continuity.

It also creates scalability.

A country does not need to rely indefinitely on a small group of exceptional hackers.

It can build a system capable of producing new operators.

The largest training stream is particularly revealing.

Approximately 120 students were reportedly associated with VUS 141600 during 2024.

That is not the profile of a tiny underground hacking team.

It resembles a workforce-development program.

The inclusion of reserve personnel is equally important.

A military cyber capability needs depth.

Operators can leave.

Personnel can be reassigned.

Operations can increase suddenly.

Reserve training provides an additional layer of capacity.

The curriculum also demonstrates an integrated understanding of cyber conflict.

Students are not simply taught how to attack.

They are taught how to detect attacks.

They are taught how to analyze malware.

They are taught how to reconstruct an intrusion.

They are taught how to map infrastructure.

They are taught how to protect systems.

They are taught how to deceive adversaries.

That creates personnel who can potentially understand both sides of a cyber operation.

The attacker-versus-defender model is especially valuable.

It teaches students to think dynamically rather than memorize tools.

An attacker changes tactics.

The defender responds.

The attacker adapts.

The defender prioritizes.

That cycle resembles real cyber operations.

The connection to military internships makes the model even stronger.

Academic knowledge becomes operational exposure.

Operational exposure becomes institutional experience.

Institutional experience can become military placement.

That is a career pipeline.

The GRU connections make the pipeline strategically relevant.

Unit 26165 and Unit 74455 have already been associated publicly with major Russian cyber campaigns.

The Bauman records potentially show part of the machinery feeding personnel into those organizations.

This also explains why individual APT campaigns should not always be analyzed in isolation.

A campaign is the visible output.

Training is part of the production system.

Recruitment is another part.

Personnel management is another.

Command oversight is another.

Military placement is another.

The leak provides visibility into several of those layers simultaneously.

That is unusual.

There is another important lesson for defenders.

Cybersecurity programs often concentrate heavily on technical indicators.

IP addresses.

Domains.

Malware hashes.

Command-and-control infrastructure.

Exploit patterns.

Those indicators are valuable, but they are temporary.

Human infrastructure can be more persistent.

Education programs can reveal future specialization.

Military placements can reveal organizational relationships.

Academic research can reveal technical priorities.

Training exercises can expose defensive assumptions.

Personnel movements can potentially reveal organizational changes.

Taken together, those signals can provide strategic intelligence long before a new campaign becomes visible.

The Bauman leak also highlights the growing importance of educational institutions in state cyber intelligence.

Universities are not necessarily separate from national-security ecosystems.

Technical universities can become talent pools.

Military departments can become recruitment channels.

Research programs can support operational capabilities.

Training centers can become bridges between academia and intelligence organizations.

That means universities themselves can become strategically significant targets for intelligence collection.

There is also an important defensive lesson.

Organizations should not assume that protecting operational infrastructure alone is enough.

Training institutions may contain information about future capabilities.

Curricula reveal priorities.

Personnel records reveal relationships.

Internships reveal organizational connections.

Conference papers reveal research interests.

Administrative documents reveal command structures.

A single compromise can therefore produce intelligence far beyond passwords or financial data.

The leak also shows why metadata matters.

The content of a document may look harmless.

Its metadata can reveal the system that created it.

Usernames can connect documents.

Folder structures can reveal internal organization.

Calendar records can reveal meetings.

File histories can expose relationships.

Together, these small clues can reconstruct an institutional environment.

That is exactly why metadata hygiene remains important.

The larger strategic conclusion is straightforward.

Russia’s military cyber capability should not be understood simply as a collection of mysterious hacker groups.

It appears to include institutions capable of developing the next generation of operators.

That makes the cyber threat more durable.

Destroying one tool does not destroy the workforce.

Disrupting one server does not destroy the training system.

Sanctioning one operator does not eliminate the next generation.

The most consequential question is therefore not only, “Who conducted the last attack?”

It is also, “Who is being trained to conduct the next one?”

The Bauman documents provide an unusually direct look at that question.

Deep Analysis: What the Leak Means for Cyber Defenders

Start With Metadata

Security teams investigating suspicious documents should examine metadata rather than relying exclusively on visible content.

exiftool suspicious_document.docx

For a larger investigation, metadata can be collected across a controlled evidence directory:

find ./evidence -type f -print0 | xargs -0 exiftool

Identify File Types

A basic inventory can quickly show what an archive contains:

find ./evidence -type f | sort
File classification can then help separate documents, images, archives and executable material:
file ./evidence/

Search for Organizational Clues

Investigators can search authorized forensic collections for recurring organizational terms:

grep -RniE "GRU|military|intelligence|training|internship|cyber" ./evidence/

The objective is not simply to find passwords or malicious code.

The objective is to identify relationships.

Build a Timeline

File timestamps can help investigators reconstruct activity:
find ./evidence -type f -printf '%TY-%Tm-%Td %TH:%TM:%TS %p
' | sort

A timeline can reveal when documents were created, modified or collected.

Look for Suspicious Network References

If documents contain URLs or infrastructure references, investigators can extract them for controlled analysis:

grep -RhoE 'https?://[^[:space:]"<>]+' ./evidence/ | sort -u

Any discovered infrastructure should be handled through established threat-intelligence and incident-response procedures rather than accessed directly from an investigative workstation.

Calculate Evidence Hashes

Preserving evidence integrity is essential:

sha256sum ./evidence/ > evidence_hashes.txt

For larger collections:

find ./evidence -type f -print0 | xargs -0 sha256sum > evidence_hashes.txt

Examine Archive Structure Safely

Archives can reveal important organizational information, but they should be processed in isolated environments.

unzip -l suspicious_archive.zip

Do not execute unknown binaries simply because they appear inside a leaked archive.

Search for Repeated Identities

Repeated usernames, email addresses, document authors and directory names can reveal relationships across an institutional collection.

grep -RniE "Author|Creator|Last Modified By|Company|Manager" ./evidence/

Build the Bigger Picture

The most valuable intelligence often emerges when technical indicators are combined with organizational data.

A malware sample alone tells part of the story.

A malware sample plus its developer metadata tells more.

A developer plus a department tells more.

A department plus an internship program tells more.

An internship program plus military placement can reveal an entire personnel pipeline.

That is the analytical lesson behind the Bauman leak.

Evidence Assessment

✅ The core leak is supported by DomainTools research. DomainTools reports analyzing approximately 1,600 files and concludes that the material originated from Bauman Moscow State Technical University’s environment.

DomainTools

✅ The GRU and military-unit connections are substantially documented. DomainTools and its reporting partners identified links between Department No. 4, graduates and military units publicly associated with APT28 and Sandworm.

DomainTools

❌ It would be inaccurate to say every graduate became an APT28 or Sandworm hacker. The available evidence establishes reported assignments and institutional relationships, but does not prove that every named graduate personally participated in specific cyberattacks.

DomainTools

Prediction

(+1) Russia Will Continue Expanding Institutional Cyber Training

Russia is likely to continue treating cyber capabilities as a long-term military workforce rather than relying exclusively on a handful of elite operators.

(+1) University-Military Cyber Pipelines Will Become More Important

Technical universities and military education centers are likely to remain important recruitment and specialization channels as cyber operations become increasingly integrated with conventional military planning.

(+1) Human-Centric Threat Intelligence Will Grow

Security researchers will increasingly track personnel movement, education, research programs and organizational relationships alongside malware, domains and IP addresses.

(-1) Disrupting Individual APT Groups Will Not Eliminate the Threat

Taking down infrastructure or identifying individual operators is unlikely to permanently remove the capability if the underlying recruitment and training system remains intact.

(+1) Leaked Academic Records Will Become Valuable Intelligence Sources

Future investigations may increasingly focus on educational and administrative data because these records can reveal the people, priorities and institutional relationships behind future cyber operations.

The Bigger Warning Hidden in the Bauman Documents

The Bauman leak offers something rarely visible in cybersecurity reporting: a glimpse of the machinery behind the operators.

APT groups are usually discussed as if they appear fully formed.

They do not.

Behind every sophisticated military cyber capability are programmers, analysts, intelligence officers, defenders, planners, researchers, instructors and technical specialists.

Someone has to train them.

Someone has to evaluate them.

Someone has to place them.

Someone has to replace them.

The documents from Department No. 4 suggest that Russia has built an institutional mechanism for doing exactly that.

That may ultimately be the most important lesson from this leak.

The cyber battlefield is not sustained only by malware and infrastructure.

It is sustained by people.

And if the training pipeline continues, the next generation of Russian military cyber operators may already be sitting in classrooms, completing examinations, participating in exercises and preparing for their first assignments.

▶️ Related Video (78% Match):

🕵️‍📝Let’s dive deep and fact‑check.

🎓 Live Courses & Certifications:

Join Undercode Academy for Verified Certifications

🚀 Request a Custom Project:

Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands

References:

Reported By: x.com
Extra Source Hub (Possible Sources for article):
https://www.digitaltrends.com
Wikipedia
OpenAi & Undercode AI

Image Source:

Unsplash
Undercode AI DI v2

🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]

💬 Whatsapp | 💬 Telegram

📢 Follow UndercodeNews & Stay Tuned:

𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin | 🦋BlueSky | 🐘Mastodon | 📺Youtube