Bauman Leak Reveals GRU Training in Malware, Exploitation, Adversary Emulation and Cyber Warfare

Leaked documents indicate that Bauman Moscow State Technical University’s Department No. 4 operated as a long-term training pipeline for Russian military intelligence and cyber operations.

The records describe a structured program that trained future cyber operators, analysts, planners, defenders, and reserve personnel for organizations linked to the Russian General Staff, commonly known as the GRU.

The material was reviewed by an international media consortium including The Insider, The Guardian, Le Monde, Der Spiegel, Delfi, and VSquare.

It reportedly contains course records, student rosters, internship plans, presentations, military specialty codes, administrative files, and internal correspondence.

Department No. 4 reportedly trained around 250 career and reserve students across six academic years. Students were divided into three main specialties: Special Intelligence Service, information-technical effects and protection, and information technology protection.

The documents show that the department’s mission extended beyond conventional university cybersecurity education.

It combined military intelligence, offensive cyber operations, network defense, communications security, technical surveillance, and information warfare.

The program also included placements at military units and academies, allowing students to apply classroom training in supervised operational environments.

Leaked GRU Cyberwarfare Training

The largest specialty was reportedly VUS 141600, described as the use of forces and means for information-technical effects and protection against such effects.

Around 120 students were enrolled in this stream in 2024, nearly half of the department’s total population.

Leaked GRU Cyberwarfare Training (Source: domaintools)
Leaked GRU Cyberwarfare Training (Source: domaintools)

Its curriculum focused on both offensive and defensive cyber activity. Students studied password attacks, server exploitation, malware development, vulnerability research, penetration testing, cryptography, steganography, intrusion detection, technical deception, and infrastructure mapping.

One lecture described “information-technical weapons” as tools and methods designed to alter, destroy, copy, block, or manipulate information.

The material also discussed overcoming protection systems, disrupting networks, conducting disinformation, and targeting high-technology infrastructure.

The leak suggests that Bauman did not treat red-team and blue-team skills as separate disciplines.

Students were trained to understand attacker behavior, detect intrusions, block operations, conceal systems, deceive adversaries, and potentially conduct counteractions against hostile infrastructure.

FOCA metadata analysis of users from files (Source: domaintools)
FOCA metadata analysis of users from files (Source: domaintools)

The files also point to practical malware-analysis training. Conference papers reportedly examined phishing operations, self-extracting archives, remote-access tools, command-and-control infrastructure, script deobfuscation, and system-call monitoring.

Students also participated in attacker-versus-defender exercises that required them to select tactics, respond to opposing activity, and evaluate outcomes.

Reporting identified Bauman graduates assigned to Military Unit 26165, widely associated with APT28 or Fancy Bear, and Military Unit 74455, commonly linked to Sandworm.

Unit 26165 is generally associated with cyber espionage and intelligence collection, while Sandworm has been tied to disruptive and destructive cyber operations, domaintools said.

The documents also reportedly connect senior GRU officers to Department No. 4’s oversight structure. Viktor Netyksho, identified as a former commander of Unit 26165, was named among personnel involved in student supervision and evaluation.

Detect, investigate, and respond faster with in-browser data inspection from ANY.RUN-> Power your SOC with ANY.RUN

Varshini
Varshini
Varshini is a Cyber Security expert in Threat Analysis, Vulnerability Assessment, and Research. Passionate about staying ahead of emerging Threats and Technologies..

Trending News

Related Stories