Inside Russia’s Hidden Cyberwar School: How Bauman University Became a Reported Pipeline for GRU Hackers + Video

Listen to this Post

Featured ImageA University, a Secret Department, and a Much Bigger Mission

For decades, universities have been places where mathematics, engineering, computer science, and cybersecurity skills are developed for civilian and military purposes alike. But a major international investigation published in May 2026 points to something considerably more secretive at one of Russia’s most prestigious technical institutions: Bauman Moscow State Technical University.

According to more than 2,000 leaked internal documents examined by The Insider, The Guardian, Le Monde, Der Spiegel, Delfi, and VSquare, the university’s Department No. 4 appears to have functioned as a concealed training pipeline for personnel destined for Russia’s military intelligence service, the GRU. The documents reportedly include student lists, course plans, internal correspondence, military assignments, internship records, presentations, and personnel information.

Le Monde.fr

+2

The Insider

+2

What makes the investigation particularly significant is not simply that students studied cybersecurity. Modern universities routinely teach penetration testing, cryptography, malware analysis, network defense, and vulnerability research. The extraordinary element described in the leaked material is the apparent combination of those technical skills with military intelligence, information warfare, psychological operations, communications security, and preparation for service in GRU-linked units.

The result is a picture of cybersecurity education being integrated into a broader state security apparatus.

Department No. 4 Was Reportedly Anything but Ordinary

The department was reportedly associated with the university’s military training center and carried the relatively unremarkable name “Special Training.” It was apparently absent from the university’s public organizational structure, with the investigation noting that the public-facing structure jumps from Department No. 3 to Department No. 5.

The Insider

That seemingly small administrative detail becomes important when viewed alongside the leaked records.

The documents reportedly show students being prepared for several military specialties involving information operations, technical protection, intelligence, communications, and cybersecurity. DomainTools, which separately analyzed the reporting and leaked material, described Department No. 4 as focusing on cyberwarfare, defense, UAV-related capabilities, communications, and related technologies.

DomainTools

This is where the story moves beyond the familiar concept of a university cybersecurity program.

The apparent objective was not simply to produce security engineers who could protect corporate networks. Instead, the training appears to have been designed to create personnel capable of operating across the entire cyber conflict spectrum—from identifying vulnerabilities and analyzing malware to defending networks, conducting technical reconnaissance, supporting information operations, and potentially attacking adversary infrastructure.

A Curriculum Built Around Offensive and Defensive Cyberwarfare

The leaked curriculum reportedly included subjects such as password attacks, server exploitation, malware development, vulnerability research, penetration testing, cryptography, steganography, intrusion detection, technical deception, and infrastructure mapping.

That mixture is significant.

In conventional cybersecurity education, offensive techniques are often taught because defenders need to understand how attackers operate. Ethical hacking courses, red-team exercises, vulnerability assessments, and malware analysis are standard parts of many professional programs.

But the investigation indicates that Department No. 4 went further by placing these capabilities inside an explicitly military framework.

The documents reportedly describe “information-technical weapons” as methods and tools capable of altering, destroying, copying, blocking, or manipulating information. Training also reportedly addressed ways of overcoming protective systems, disrupting networks, conducting information operations, and targeting advanced technological infrastructure.

Le Monde.fr

+1

That distinction matters because cyber conflict is no longer limited to stealing files.

A modern military cyber operation can involve intelligence collection, credential theft, network access, disruption, deception, psychological operations, infrastructure manipulation, and long-term persistence. A training program that combines these disciplines can produce operators who understand both the technical and strategic dimensions of cyber conflict.

Red Team and Blue Team Skills Were Apparently Blended

One of the most interesting aspects of the reported curriculum is the apparent absence of a rigid boundary between attacker and defender training.

Students reportedly learned how attackers identify weaknesses, how defenders detect suspicious activity, how networks can be concealed, how security systems can be bypassed, and how adversaries can be deceived.

That approach makes sense from a military perspective.

A defender who understands offensive methodology can recognize the signals of an intrusion more quickly. Conversely, an offensive operator who understands defensive architecture can identify which systems are likely to detect an attack.

The danger arises when that knowledge is combined with operational assignments and intelligence objectives.

The same person who learns how to identify a vulnerability for defensive purposes may also understand how that vulnerability could be weaponized. The difference is not necessarily the technical skill itself; it is the mission, authorization, and organization controlling that skill.

Malware Analysis and Practical Cyber Exercises

The documents reportedly reveal practical work involving phishing, self-extracting archives, remote-access tools, command-and-control infrastructure, script deobfuscation, and system-call monitoring.

Students also reportedly participated in attacker-versus-defender exercises in which opposing teams selected tactics, reacted to one another, and evaluated the results.

That kind of exercise can be extremely valuable for legitimate cybersecurity education. It resembles the architecture of modern cyber ranges used by governments, universities, and private security companies.

But in this case, the surrounding evidence gives those exercises a different significance.

The reported program apparently connected academic training with military placements and future assignments. Rather than learning cybersecurity solely as an academic discipline, students could reportedly transition from classroom exercises into military environments where their technical knowledge could be applied to operational problems.

The Reported GRU Connection

The strongest part of the investigation concerns the alleged connection between Department No. 4 graduates and GRU military units.

The reporting identified graduates associated with Military Unit 26165, widely linked to APT28 or Fancy Bear, and Military Unit 74455, associated with Sandworm and tracked by security researchers as APT44.

The Guardian

+1

These organizations have very different operational histories but share one important characteristic: both have been repeatedly associated by governments and cybersecurity researchers with Russian military intelligence operations.

Unit 26165 has been associated with cyber espionage and intelligence collection, while Unit 74455 has been linked to disruptive and destructive cyber operations, including attacks against critical infrastructure.

DomainTools

The significance is therefore not that Bauman graduates simply found jobs in cybersecurity.

The investigation suggests that some graduates entered organizations at the center of Russia’s military cyber apparatus.

Viktor Netyksho and the Instructor Connection

The leaked records reportedly contain another striking detail: senior GRU personnel allegedly participated in the supervision or evaluation of students.

One name highlighted by the investigation is Viktor Netyksho, a former commander associated with Unit 26165. According to Le Monde’s reporting, a 2024 examination-related document was signed by a person identified as Netyksho.

Le Monde.fr

That matters because it potentially transforms the relationship between the university and the intelligence service from an informal employment pipeline into something considerably more integrated.

If serving or former intelligence officers are directly involved in evaluating students, the university is no longer merely producing graduates who later happen to enter military service.

It suggests the intelligence organization may have a role in identifying, evaluating, and preparing future personnel before graduation.

Students Were Reportedly Sent Into Military and Defense Environments

The leaked records reportedly describe internships and placements at military units, academies, and defense-related organizations.

Some companies connected to these placements have reportedly been sanctioned by Ukraine, the European Union, or the United States because of their relationship with Russia’s defense sector.

Le Monde.fr

This internship model is particularly important.

A university classroom can teach theory. A cyber range can simulate attacks. But an operational placement exposes students to real organizational structures, procedures, communications systems, and military requirements.

That creates a bridge between education and employment.

In cybersecurity, practical experience is often the difference between knowing a concept and being able to apply it under pressure. A military institution that controls both stages can potentially shape personnel from their earliest technical training through their eventual operational roles.

The Human Pipeline Behind the Technology

One of the most revealing aspects of the investigation is the scale of the reported recruitment pipeline.

The original material describes approximately 250 career and reserve students across six academic years, while reporting from the international consortium indicates that the leaked material covers thousands of internal documents and identifies multiple students moving toward GRU-related careers.

Le Monde.fr

+1

The numbers should be interpreted carefully.

The existence of a relatively small department does not mean that only a few people matter. A military intelligence organization does not need tens of thousands of operators to generate significant effects.

A highly trained specialist who understands advanced networking, malware, cryptography, intelligence collection, and operational security can have an outsized impact.

Cyberwarfare is unusual in that a relatively small number of technically sophisticated operators can potentially influence systems used by millions of people.

From Cybersecurity to Information Warfare

The most unsettling part of the investigation may actually be the material that goes beyond computers.

The reporting describes courses involving information warfare, psychological manipulation, propaganda production, and experimental psychology. Students reportedly learned how to create social-media videos designed to manipulate perceptions around controversial issues.

Le Monde.fr

+1

This demonstrates how modern state cyber operations increasingly blur traditional boundaries.

Cybersecurity, espionage, propaganda, social engineering, intelligence collection, and psychological influence can all reinforce one another.

A compromised account can provide intelligence.

Intelligence can inform a propaganda campaign.

A propaganda campaign can influence public perception.

Social engineering can then be used to obtain additional credentials.

The entire operation becomes a feedback loop rather than a collection of isolated activities.

The Importance of Information Manipulation

Traditional military doctrine often separates physical warfare from intelligence operations and psychological operations.

Cyberwarfare makes that separation increasingly difficult.

A network intrusion can steal information, disrupt infrastructure, expose sensitive material, and create psychological pressure at the same time.

Likewise, an information campaign can exploit stolen documents to create political consequences.

This is why the reported inclusion of propaganda and psychological training alongside technical cybersecurity subjects is so important. It indicates a broader understanding of conflict in which information itself becomes a battlefield.

The Reported Connection to APT28 and Sandworm

The association with APT28 and Sandworm gives the leaked training records additional weight.

APT28, also known as Fancy Bear, has long been associated with Russian military intelligence and cyber espionage operations. Sandworm, meanwhile, has been associated with destructive and disruptive attacks, including operations targeting critical infrastructure.

DomainTools’ analysis of the leaked material independently highlighted graduates associated with Military Units 26165 and 74455 and connected senior GRU officers with student oversight.

DomainTools

This does not mean every student in Department No. 4 became a cyber operator.

Nor does it mean every course participant was destined for offensive operations.

But the documented links between students, military units, instructors, and internships create a much stronger picture than a simple university cybersecurity program.

The Broader Meaning for Western Defenders

For defenders outside Russia, the investigation offers an important warning.

Cyber threats do not appear from nowhere.

Behind sophisticated campaigns are people who must be recruited, educated, trained, tested, assigned, and managed.

The Bauman investigation reportedly exposes part of that human infrastructure.

This is valuable intelligence because cybersecurity organizations frequently concentrate on malware signatures, infrastructure indicators, vulnerabilities, and attacker techniques.

Those are essential.

But understanding the ecosystem that produces attackers can be equally important.

Why Universities Have Become Strategic Assets

Universities possess something governments and intelligence services desperately need: talented young people.

Students entering university may already have strong programming, mathematics, networking, engineering, or cybersecurity abilities.

A state that identifies these students early can provide specialized training before they enter the private sector.

The result is effectively a talent pipeline.

Instead of recruiting fully trained specialists later, an organization can help shape specialists from the beginning.

That model is not unique to Russia. Major governments around the world invest heavily in university research, cyber education, scholarships, military programs, and talent development.

What makes the Bauman case extraordinary is the alleged secrecy and the direct connection to military intelligence operations.

A New Generation of Cyber Operators

The investigation suggests that Russia is not simply relying on a handful of experienced hackers.

It is reportedly investing in a younger generation.

That distinction matters.

Experienced operators eventually leave the field, retire, become exposed, or lose access to operational infrastructure. A sustainable cyber capability requires replacement.

Universities can provide exactly that replacement.

If the leaked records accurately represent the

The Strategic Advantage of Early Training

Early training provides another advantage: specialization.

A student can be identified as particularly strong in cryptography, malware analysis, network exploitation, communications, intelligence analysis, or information operations.

The organization can then guide that student toward the role where their abilities have the greatest operational value.

This is similar to how elite military organizations develop specialists.

The difference is that the battlefield is digital.

Deep Analysis: What Defenders Can Learn From the Reported Pipeline

Understand the Human Layer

The most important lesson is that cyber defense should not focus exclusively on malicious code.

Attackers are people operating within organizations.

Their skills, training, preferred techniques, infrastructure, and operational objectives can all reveal patterns.

Security teams should therefore combine technical telemetry with threat intelligence about known adversary groups.

Monitor Authentication Behavior

Organizations should pay close attention to unusual authentication patterns, especially impossible travel, abnormal VPN usage, unfamiliar devices, suspicious service-account activity, and unexpected privilege escalation.

For Linux systems, defenders can begin with basic authentication review:

sudo journalctl --since "24 hours ago" | grep -Ei "ssh|sudo|authentication|failed|accepted"

This does not identify a specific Russian operation by itself. It simply helps security teams investigate unusual access patterns.

Review Network Connections

Unexpected outbound connections can reveal command-and-control activity, unauthorized remote-access software, or compromised hosts.

A basic Linux investigation can begin with:

ss -tulpn

For established connections:

ss -tpn

These commands should be interpreted alongside normal baseline behavior rather than treated as automatic indicators of compromise.

Search for Suspicious Processes

When investigating a potentially compromised Linux system, defenders can examine running processes:

ps aux --sort=-%cpu | head -30

For network-related processes:

ps aux | grep -Ei "ssh|curl|wget|nc|python|perl|bash"

These commands are useful for triage, although legitimate administrators and applications may produce the same process names.

Inspect Persistence Mechanisms

Attackers frequently attempt to survive reboots.

Defenders can review scheduled tasks and system services:

systemctl list-unit-files --state=enabled

And user-level scheduled jobs:

crontab -l
sudo ls -la /etc/cron.

The goal is not to hunt for a particular actor but to establish whether unauthorized persistence exists.

Analyze DNS Activity

DNS telemetry can reveal suspicious infrastructure, especially when combined with newly registered domains, unusual query volumes, or algorithmically generated names.

A basic investigation might include:

sudo journalctl | grep -Ei "dns|named|resolved"

Enterprise defenders should ideally collect DNS logs centrally rather than relying only on individual endpoints.

Look for Command-and-Control Patterns

Security teams should investigate systems making persistent outbound connections to unfamiliar infrastructure.

Useful indicators include:

Long-lived encrypted sessions

Repeated beacon-like connections

Unusual destination countries

Newly observed domains

Connections from servers that normally have no internet access

Unexpected DNS tunneling patterns

Rare user agents

Connections initiated by unusual processes

No single indicator proves compromise.

The value comes from correlation.

Build Behavioral Detection

Signature-based detection remains useful, but advanced operators can modify malware, infrastructure, and delivery mechanisms.

Behavior is harder to disguise.

A security platform should therefore correlate process creation, credential access, privilege escalation, lateral movement, persistence, and unusual network communication.

Separate Critical Systems

The reported focus on military and strategic infrastructure reinforces the importance of segmentation.

Critical systems should not be directly reachable from ordinary user networks.

Organizations should minimize:

Internet

|

DMZ

|

Application Network

|

Internal Network

|

Restricted Systems

|

Critical Infrastructure

Every transition should require explicit authentication and authorization.

Protect Credentials Aggressively

If an attacker gains administrative credentials, many defensive boundaries become irrelevant.

Organizations should therefore prioritize phishing-resistant authentication, privileged access management, hardware-backed credentials where appropriate, and strict separation between administrative and ordinary accounts.

Treat Cybersecurity as Intelligence

The Bauman story demonstrates why defensive cybersecurity increasingly resembles intelligence work.

Security teams should ask:

Who is attacking us?

What capabilities do they possess?

What infrastructure do they rely on?

What organizations are associated with them?

What techniques remain consistent across campaigns?

These questions can provide more strategic value than simply asking which malware family was detected.

What Undercode Say:

The Bauman investigation is much bigger than a story about a secret university department.

It is a story about how states build cyber capabilities.

The most important revelation is the apparent connection between education and intelligence recruitment.

Cyberwarfare requires talent.

Talent requires training.

Training requires institutions.

And institutions can quietly become part of national security infrastructure.

That is why universities are increasingly important to cyber strategy.

The leaked documents reportedly show a pipeline in which students could move from academic education toward military intelligence assignments.

That creates continuity.

It also creates institutional memory.

A cyber operation conducted today may be based on techniques developed years earlier.

An operator working today may have been identified as a promising student years before joining an intelligence unit.

This means defenders cannot look only at

They need to understand the ecosystem behind the attack.

The reported curriculum is particularly revealing because it combines offensive and defensive skills.

That combination is not inherently suspicious.

In fact, the best defenders often understand offensive techniques extremely well.

The critical question is who controls those capabilities and for what purpose.

The reported inclusion of malware development, vulnerability research, password attacks, network exploitation, cryptography, and technical deception indicates a highly technical program.

Adding information warfare and psychological operations creates another layer.

It means technical access and human influence can potentially operate together.

That is increasingly characteristic of modern hybrid warfare.

A phishing campaign can steal credentials.

Stolen credentials can provide network access.

Network access can provide intelligence.

That intelligence can support a political influence operation.

The influence operation can then create confusion that makes attribution and response more difficult.

Cyber and information warfare therefore reinforce each other.

This is why the reported Bauman program deserves attention from security professionals.

The issue is not simply that students learned hacking.

Thousands of cybersecurity students around the world learn ethical hacking every year.

The issue is the alleged operational pipeline surrounding those skills.

Military placements matter.

Intelligence-linked instructors matter.

Graduate assignments matter.

Internal evaluation documents matter.

When all those pieces appear together, the strategic picture becomes much clearer.

The investigation also demonstrates the importance of leaked administrative documents.

A malware sample may reveal what an attacker does.

An internal university document may reveal how attackers are produced.

That second category of intelligence can be extraordinarily valuable.

It can expose recruitment methods, institutional relationships, training priorities, and future talent pipelines.

There is also an important lesson for governments.

Cyber defense should include workforce intelligence.

Knowing the technical indicators of APT28 or Sandworm is useful.

Understanding how those organizations recruit and develop personnel can provide another layer of strategic awareness.

The reported scale of the program is also important.

A few hundred students may sound small compared with a major university.

But elite cyber operations do not require enormous armies.

A small number of highly skilled operators can compromise major organizations.

That asymmetry makes cyberwarfare particularly dangerous.

One trained specialist can potentially exploit weaknesses affecting thousands of systems.

The story also reinforces why critical infrastructure deserves special protection.

Energy, telecommunications, transportation, government, defense, healthcare, and financial systems are all potential targets in a prolonged cyber conflict.

Their security cannot depend solely on perimeter defenses.

They require segmentation, identity security, monitoring, incident response, threat intelligence, and resilient recovery capabilities.

Another lesson is that defensive teams should practice against realistic adversaries.

Cyber ranges, red-team exercises, purple-team operations, and incident-response simulations can help organizations identify weaknesses before hostile actors do.

The difference between legitimate security research and offensive cyber operations is authorization and intent.

The same technical knowledge can be used to defend a network or attack one.

That makes governance just as important as technical capability.

The Bauman investigation also raises uncomfortable questions about the future.

If universities become increasingly integrated into national cyber programs, competition for technical talent will become more intense.

Countries will compete not only for experienced hackers but for students.

Scholarships, research programs, military academies, internships, competitions, and specialized laboratories may all become part of strategic cyber recruitment.

The global cybersecurity workforce is therefore becoming a geopolitical resource.

Russia is not alone in recognizing this.

The United States, China, European governments, Israel, and other technologically advanced nations have invested heavily in cybersecurity education and cyber talent.

The difference between legitimate national cybersecurity development and offensive state activity must therefore remain clearly understood.

The Bauman case is especially concerning because the leaked material reportedly connects education with organizations accused of conducting espionage and destructive cyber operations.

That connection deserves continued scrutiny.

Ultimately, the biggest lesson is simple:

Cyberwarfare begins long before the first malicious packet reaches a victim.

It begins in classrooms.

It begins in recruitment.

It begins in training.

It begins with identifying people who have unusual technical abilities.

And if the investigation is accurate, Department No. 4 was designed to turn those abilities into a long-term military capability.

That makes this story less about one university and more about the industrialization of cyber talent.

✅ The Department No. 4 Investigation Is Real

The international investigation was published in May 2026 by The Insider and partner organizations including The Guardian, Le Monde, Der Spiegel, Delfi, and VSquare. The reporting was based on more than 2,000 internal documents attributed to Bauman’s Department No. 4.

Le Monde.fr

+2

The Insider

+2

✅ GRU-Linked Units Are Part of the Reporting

Multiple reports identify graduates connected with Military Unit 26165 and Military Unit 74455, which are widely associated with APT28/Fancy Bear and Sandworm respectively. DomainTools independently summarized the same connections in its threat-intelligence analysis.

The Guardian

+1

✅ Offensive Cybersecurity Training Was Reported

The investigation describes coursework involving hacking, vulnerability exploitation, malware creation, cryptography, network security, and information warfare. The reporting specifically says students were taught capabilities extending beyond conventional defensive cybersecurity.

Le Monde.fr

+1

⚠️ Some Numerical Details Should Be Treated Carefully

The supplied article says Department No. 4 trained approximately 250 career and reserve students across six academic years and identifies around 120 students in one specialty in 2024. The broader investigation confirms substantial student records, but individual totals can vary depending on the academic years, specialty, and document set being counted. The numbers should therefore not be presented as an exact current enrollment figure without qualification.

Le Monde.fr

+1

⚠️ The GRU Pipeline Is Strongly Reported, but Individual Roles Require Attribution

The documents and investigation provide substantial evidence of links between students, instructors, military units, and the GRU. However, not every student in Department No. 4 should automatically be described as an intelligence operative or hacker. Individual assignments and operational roles need to be evaluated separately.

The Insider

+1

Prediction

(+1) Russia Will Continue Expanding University-to-Cyber-Intelligence Pipelines

The most likely long-term outcome is that Russia will continue investing in technical education as a source of military and intelligence talent.

The strategic logic is straightforward: cyber capabilities depend on highly educated specialists, and developing those specialists internally reduces dependence on external recruitment.

Future programs are likely to place even greater emphasis on artificial intelligence, autonomous systems, malware analysis, cryptography, electronic warfare, influence operations, and critical-infrastructure targeting.

For Western organizations, this means the cyber threat landscape will increasingly involve younger operators with sophisticated technical backgrounds.

The next generation of cyber conflicts may therefore be shaped less by isolated criminal hackers and more by highly organized teams that have been developing their capabilities since university.

The Bauman documents offer a rare glimpse into how that pipeline can be constructed—and why cybersecurity is becoming inseparable from geopolitics.

▶️ Related Video (78% Match):

🕵️‍📝Let’s dive deep and fact‑check.

🎓 Live Courses & Certifications:

Join Undercode Academy for Verified Certifications

🚀 Request a Custom Project:

Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands

References:

Reported By: cyberpress.org
Extra Source Hub (Possible Sources for article):
https://www.reddit.com/r/AskReddit
Wikipedia
OpenAi & Undercode AI

Image Source:

Unsplash
Undercode AI DI v2

🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]

💬 Whatsapp | 💬 Telegram

📢 Follow UndercodeNews & Stay Tuned:

𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin | 🦋BlueSky | 🐘Mastodon | 📺Youtube