Leaked Documents Expose Bauman University’s Hidden Department That Trained Hackers, Propagandists, and Malware Developers for the GRU
More than 2,000 internal documents from Bauman Moscow State Technical University have been reviewed by an international media consortium, and the picture they describe is not a conventional cybersecurity program. The files span academic and administrative records through 2025.
“Recently leaked records show that Bauman Moscow State Technical University’s Department No. 4 operated as a long-term training pipeline for Russian military intelligence and cyber operations.” reads the report published by DomainTools. “The department served several elements of the Russian General Staff and trained roughly 250 career and reserve students across three specialties: special intelligence (“Служба специальной разведки”), operational information-technical effects (“Применение сил и средств информационно-технического воздействия и защиты от информационно-технического воздействия”), and information-technology protection (”3ащита информационных технологий”). “

Department No. 4, also called “Special Training,” operated inside Bauman’s Military Training Center and doesn’t appear anywhere on the university’s public organizational chart. The GRU’s talent pipeline tends not to announce itself.
The investigation was carried out by a group of media outlets including The Insider, The Guardian, Le Monde, Der Spiegel, Delfi, VSquare, and FRONTSTORY.PL. DomainTools researchers also analyzed the leaked files independently. A DarkForums user known as “Losyash” may have shared the data, but it has not been confirmed that the account originally obtained the records.
The department trained students in three military specialties. These covered special intelligence, information and cyber operations, and the protection of IT systems. In practice, the courses included espionage, offensive cyber operations, electronic reconnaissance, secure systems, and influence operations.
Around 250 career and reserve students went through the program over six academic years. Researchers estimate that 10 to 15 students each year were selected for GRU-related assignments before graduating.
“Technical protection training covered cryptography and steganography, as well as code analysis and intrusion detection. Students were also trained in hardware inspection, the discovery of physical implants, and the identification of undocumented device functions. These subjects point to possible assignments in technical counterintelligence and supply chain security, as well as firmware analysis and embedded system inspection. Other likely functions include secure procurement and the protection of specialized military platforms.” continues the report. “The files also reveal an underreported malware-analysis and cyber threat intelligence program.”
One advanced practical assignment required the creation of a social-media video built around what the course materials called “manipulation, pressure, and hidden propaganda.” This counted as coursework.
Course materials defined “information-technical weapons” as tools and methods designed to alter, destroy, copy, block, or manipulate information. Red-team and blue-team functions were treated as a single discipline, not separate tracks, which mirrors how Russian military doctrine actually deploys cyber operators.
The personnel links are what make this more than a training curiosity. The leaked records identify Major General Viktor Netyksho as involved in Department No. 4’s oversight. Netyksho was the former commander of Military Unit 26165, the GRU formation publicly associated with APT28, also tracked as Fancy Bear, Sofacy, and STRONTIUM. He was among the 12 GRU officers indicted by the United States in 2018 for interference in the 2016 presidential election.
“Reporting identified graduates assigned to GRU Military Unit 26165 (associated with APT28) and Military Unit 74455 (associated with Sandworm), and linked senior officers, including former Unit 26165 commander Viktor Netyksho, to student oversight.” continues the report. “The data also connected senior GRU officers to the supervision and evaluation of Bauman students. Viktor Netyksho, the former commander of Unit 26165 and the 85th Main Special Service Center, is part of the department’s teaching and oversight structure.”

The reporting also identifies Aleksei Kondrashov, a 2024 Department No. 4 graduate, as linked to Military Unit 74455: the GRU’s Main Center for Special Technologies, known publicly as Sandworm, or APT44. That unit has been associated with the 2017 NotPetya attack and ongoing destructive operations against Ukraine. DomainTools also connected graduates and senior staff to Military Unit 29155, a GRU formation linked to sabotage and assassination operations in Europe.
A necessary precision: the reports establish unit placements, not individual operational involvement. A documented assignment to Military Unit 74455 doesn’t establish that a specific person participated in a specific attack. That distinction matters for both attribution work and legal proceedings.
What the leak does establish is the factory behind the names. APT28 and Sandworm are the threat groups that security teams track, attribute, and brief about. Department No. 4 is where some of the people running those operations were systematically trained, assessed, and selected.
For defenders, DomainTools summarizes the implication precisely: Russian operations should be tracked as a combined threat in which espionage, destructive attacks, military reconnaissance, technical surveillance, and influence campaigns draw on the same personnel pipelines and the same underlying doctrine. The Bauman material makes that pipeline visible for the first time at this level of institutional detail.
“The documents show that Department No. 4 is a small part of a larger long-term military training system, not a single hacking unit. The program prepared personnel for espionage and offensive cyber operations within a larger Russian technical university system.” concludes the report. “Its doctrine treated cyber warfare as more than network intrusion. Students were taught not only adversarial cyber warfare, but also a larger holistic doctrine of cyber war using both defense and attack to be better able to carry out successful campaigns.”
Follow me on Twitter: @securityaffairs and Facebook and Mastodon
(SecurityAffairs – hacking, Russia)