Leaked Records Reveal GRU’s Cyber Training Pipeline at Moscow Technical University

An archive of internal university documents has exposed how Russia’s GRU has built a structured pathway feeding into powerful cyber-espionage and sabotage units. The files, from Department No. 4 at Bauman Moscow State Technical University’s Military Training Center, outline a formal training and placement system linked to the threat groups APT28 (Fancy Bear) and Sandworm.

What the Leak Shows

Over 1,600 files were obtained that detail the intake, assessment, and deployment of around 250 students and reservists through a multi-year program stretching into 2024. The leaked materials include personnel rosters, exam records, course schedules, and placement records. Analysts confirmed their authenticity through internal consistency checks and metadata. Three specialized tracks form the backbone of the training: “Special Intelligence Service,” “Information-Technical Effects and Protection,” and “Information-Technology Protection.” The information-effects track had approximately 120 students in 2024, indicating its central role. Graduates are destined for units notably tied to Russian cyber operations—specifically, Military Unit 26165 (APT28/Fancy Bear/Forest Blizzard) and Military Unit 74455 (Sandworm).

Training Beyond the Classroom

The curriculum marries theory with practical offense and defense skills. Lessons cover password cracking, server exploits, vulnerability research, malware development, penetration testing, propaganda, and deception techniques. Additional modules focus on cryptography, code analysis, intrusion detection, and hardware assessment. Tactical simulations—like attacker-vs-defender exercises—are also central to preparation. A sample paper in the archive describes a phishing scheme using self-extracting archives and repackaged UltraVNC executables, echoing methods seen in past malicious Office-document campaigns.

Field Deployment and Operational Alignment

After defining theory and simulation, students progress to actual field placements. Special intelligence students have been stationed in cities including Kursk, Bataysk, Sevastopol, and Bugry. Those focused on information-effects are placed in Moscow, Mosrentgen, and Voronezh. Information-protection tracks lead to posting at the Krasnodar Higher Military School. Beyond cyber-attack training, one specialization involves financial-systems security—including fraud detection, payment infrastructure, transaction systems, identity control, and data protection—skills usable for both defense and offense.

The training pipeline is overseen by figures linked to GRU leadership. One former commander of Unit 26165 appears in the teaching and evaluation structure, and senior GRU officer Yuriy Shikolenko is named in official correspondence. However, there is no evidence that every trainee has engaged in malicious operations, and two named graduates from 2024 have not been publicly tied to specific cyberattacks.

For organizations facing state-sponsored cyber threats, the key takeaway is that this leak doesn’t spotlight a new malware strain or attack instrument—it reveals how human talent is cultivated systematically. Defensive strategies should emphasize long-term resilience: patching exposed systems, enforcing phishing-resistant multi-factor authentication, monitoring anomalous logins, isolating critical infrastructure, and separating office networks from operational technology systems.
As APT28 increasingly abuses edge routers and Sandworm shifts toward industrial systems targeting, understanding this human pipeline becomes vital. How were these records leaked remains unknown.

What this means: Any attack attribution or threat modelling must consider not just the tools, but the training ecosystem behind them. This leak gives rare visibility into how state actors sustain enduring campaigns through structured education, mentorship, and deployment. Observers will want to see whether similar pipelines exist in other institutions—and how defense postures evolve now that the human factor has been laid bare.