Threat Intelligence Report - University Leak Exposes Russia’s Military Cyber Training Pipeline
Threat Intelligence Report - University Leak Exposes Russia’s Military Cyber Training Pipeline
Recently leaked records have revealed that Bauman Moscow State Technical University’s Department No. 4 operated as a long-term training pipeline for Russian military intelligence and cyber operations. These records indicate that the department served several elements of the Russian General Staff. It trained roughly 250 career and reserve students across three core specialties: special intelligence (“Служба специальной разведки”), operational information-technical effects (“Применение сил и средств информационно-технического воздействия и защиты от информационно-технического воздействия”), and information-technology protection (“3ащита информационных технологий”).
The comprehensive curriculum at Department No. 4 combined both offensive and defensive techniques for cyber defense. Furthermore, it included offensive doctrine for active measures campaigns and GRU activities. Subsequent field placements then moved students from classroom instruction into various military units and academies aligned with their specialties. This process provided them with supervised exposure to intelligence operations and effectively prepared them for careers in military and government operations.
Crucially, reporting identified graduates who were assigned to GRU Military Unit 26165 (associated with APT28) and Military Unit 74455 (associated with Sandworm). The reports also linked senior officers, including former Unit 26165 commander Viktor Netyksho, directly to student oversight. Regarding the distribution of the leaked material, a DarkForums account named “Losyash” may have helped. However, its specific role in obtaining or first publishing these records remains unconfirmed at this time. Beyond its training role, the department broadly focuses on cyber warfare activities and defense, as well as UAV and communications operations and technologies.
The overarching significance of this leak is that it reveals a repeatable institutional system for producing Russian military cyber operators, analysts, planners, and defenders. 🚀
To read the complete article see: Read full article