Threat Intelligence Report: University Leak Exposes Russia’s Military Cyber Training Pipeline

Threat Intelligence Report: University Leak Exposes Russia’s Military Cyber Training Pipeline
Leaked records indicate that Bauman Moscow State Technical University’s Department No. 4 served as a long-term training pipeline for GRU cyber and intelligence personnel, with students funneled into specialties tied to special intelligence, operational cyber effects, and information-technology protection. The material also links graduates and supervisors to GRU units 26165, 74455, and 29155, and includes evidence of malware analysis, phishing, intrusion reconstruction, and other cyberwarfare instruction. #GRU #APT28 #Sandworm #MilitaryUnit26165 #MilitaryUnit74455 #DepartmentNo4

Keypoints

  • Department No. 4 at Bauman Moscow State Technical University operated as a concealed, long-term training pipeline for Russian military intelligence and cyber operations.
  • The program trained about 250 career and reserve students across three main specialties: Special Intelligence Service (VUS 093400), operational information-technical effects (VUS 141600), and information-technology protection (VUS 751100).
  • Leaked records link graduates and senior staff to GRU Military Unit 26165 (APT28/Fancy Bear) and Military Unit 74455 (Sandworm/APT44), showing direct ties to Russian cyber formations.
  • The curriculum blended offensive and defensive cyber instruction, including password attacks, server exploitation, malware creation, penetration testing, cryptography, steganography, and intrusion detection.
  • Students also received practical training through attacker-versus-defender exercises, cyber range-style activities, malware triage, infrastructure mapping, and reconstruction of attack chains.
  • Internships and field placements sent students to military units and academies in multiple Russian locations, reinforcing a structured pipeline from academic training to military application.
  • The leak includes metadata and file structure evidence supporting authenticity, suggesting the documents originated from Bauman University’s administrative and technical environment.

MITRE Techniques

  • [T1566.001 ] Phishing: Spearphishing Attachment – The paper described a campaign built around phishing, where operators used self-extracting archives as part of the intrusion chain (‘the campaign was built around phishing and self extracting archives’).
  • [T1027 ] Obfuscated Files or Information – The analysis noted that operators used renamed UltraVNC binaries and script deobfuscation was part of the training and reconstruction process (‘renamed UltraVNC binaries’; ‘script deobfuscation’).
  • [T1219 ] Remote Access Software – The article says the operators deployed renamed UltraVNC binaries, indicating use of remote access tooling for control (‘deployed renamed UltraVNC binaries’).
  • [T1057 ] Process Discovery – The material references system-call monitoring and reconstructing execution chains, which implies examining running processes and behavior (‘system-call monitoring’; ‘reconstructed the execution chain’).
  • [T1083 ] File and Directory Discovery – Metadata analysis and campaign reconstruction involved mapping infrastructure and extracting configuration parameters, consistent with discovering files, folders, and related structure (‘mapped the command infrastructure’; ‘analysis of users from files’).
  • [T1041 ] Exfiltration Over C2 Channel – The leak itself and related forum distribution show data being moved through online links and leak distribution channels (‘presented two links online to download the 1.8gb of data’).
  • [T1105 ] Ingress Tool Transfer – The campaign and coursework both referenced downloading and transferring tools/data for analysis and operational use (‘provided the leak’s distribution’; ‘two links online to download the 1.8gb of data’).
  • [T1583 ] Acquire Infrastructure – The attackers manually controlled infrastructure and the paper mapped command infrastructure, indicating acquisition and use of infrastructure for operations (‘manually controlled infrastructure’; ‘mapped the command infrastructure’).
  • [T1499 ] Endpoint Denial of Service – The curriculum described capabilities to block or disrupt information systems, and defensive measures included blocking and counteraction against adversary infrastructure (‘block’; ‘disrupt an ongoing operation’).
  • [T1070.004 ] File Deletion – The paper and curriculum discussed altering, destroying, and blocking information, reflecting destructive anti-forensic or disruption-oriented behavior (‘alter, destroy, copy, block, or steal information’).
  • [T1059 ] Command and Scripting Interpreter – The coursework included script analysis and deobfuscation, implying use of scripting interpreters in intrusion workflows (‘script analysis’).
  • [T1106 ] Native API – The paper’s focus on system-call monitoring suggests attention to low-level API/system-call behavior during malware analysis (‘system-call monitoring’).
  • [T1588.001 ] Obtain Capabilities: Malware – The curriculum explicitly included malware creation and malware-analysis research, indicating development and study of malicious code (‘malware creation’; ‘malware-analysis research’).

Indicators of Compromise

  • [Domains / forum names ] Leak distribution and discussion venue – DarkForums RU, DarkForums
  • [Account handles ] Possible leak distributor account – Losyash
  • [File count / size ] Leaked archive volume and scale – 1600 files, 1.8GB of data
  • [File types ] Document and media formats found in the leak – Word files, PowerPoint slide decks, PDF files, Excel spreadsheets, images, and .ics files
  • [Named files / documents ] Example leaked presentation and paper titles – 00000253_ГЗ 2_1 Информационно-техническое оружие.ppt, Current Issues Concerning the State and Prospects for the Development of Weapons, Military, and Special Equipment of the Aerospace Forces
  • [Organizations / units ] GRU-linked military entities referenced in the leak – Military Unit 26165, Military Unit 74455, Military Unit 29155
  • [Named software / tools ] Analysis and remote access tools referenced in the article – FOCA, UltraVNC


Read more: https://dti.domaintools.com/research/threat-intelligence-report-university-leak-exposes-russias-military-cyber-training-pipeline