VYPR
researchPublished Aug 28, 2026· 1 source

Russian University Leak Exposes GRU Cyber Training Pipeline for APT28 and Sandworm

Leaked documents from Bauman Moscow State Technical University reveal a GRU cyber training program that appears to feed personnel into notorious APT28 and Sandworm units.

A significant leak of internal documents from Bauman Moscow State Technical University's Military Training Center has provided an unprecedented glimpse into Russia's state-sponsored cyber operations. The trove of records, analyzed by DomainTools Investigations, details a structured training program designed to cultivate and deploy cyber personnel for elite GRU units, specifically those linked to the Advanced Persistent Threat (APT) groups APT28 and Sandworm. This finding is crucial as these groups are known for conducting sophisticated espionage, sabotage, and disruptive cyberattacks against governments and critical infrastructure worldwide.

The leaked archive, originating from Department No. 4 of the university's military training center, contains a wealth of information including personnel lists, academic schedules, examination results, and graduate placement records. Researchers have assessed these documents as authentic, noting their internal consistency and metadata. The material reportedly encompasses approximately 1,600 files and details the training of around 250 students. The curriculum appears to be divided into three core specialties: Special Intelligence Service, information-technical effects and protection, and information-technology protection. The "information-effects" stream, with approximately 120 students in 2024, suggests a substantial focus on developing a broad workforce capable of offensive cyber operations.

Crucially, the documents establish a direct link between graduates of this program and specific Russian military units. Personnel lists and placement records indicate that graduates have been assigned to Military Unit 26165, which is widely associated with APT28 (also known as Fancy Bear or Forest Blizzard), and Military Unit 74455, a unit frequently linked to the Sandworm collective. The distinction is significant: APT28 is primarily known for intelligence gathering and espionage, while Sandworm has a documented history of destructive attacks targeting critical infrastructure, particularly in Ukraine.

The curriculum outlined in the leaked documents is comprehensive, covering a wide array of offensive and defensive cyber capabilities. Trainees are instructed in techniques such as password attacks, server exploitation, vulnerability research, malware development, penetration testing, technical surveillance, and information manipulation. The program also includes instruction in cryptography, code analysis, intrusion detection, and hardware inspection. A 2023 conference volume further highlights advanced topics like malware triage, infrastructure mapping, anomaly detection, system-call monitoring, and attacker-versus-defender simulations, mirroring the skills required to investigate and respond to complex intrusions.

Beyond theoretical instruction, the program incorporates practical, real-world training scenarios and field placements. Students engage in "attacker-versus-defender" exercises, simulating cyber warfare environments. Graduates are then assigned to various locations for practical experience, with special-intelligence students deployed to sites like Kursk and Sevastopol, information-effects students primarily to Moscow and Voronezh, and information-protection trainees to military schools. This hands-on approach ensures that graduates are not only theoretically proficient but also operationally ready for deployment.

Notably, the leaked materials also detail a specialized track within the special-intelligence stream focused on financial systems security. This training covers payment infrastructure, transaction systems, identity controls, fraud detection, and sensitive data protection. While ostensibly for defensive purposes, this curriculum could equally equip personnel to identify and exploit vulnerabilities within banking systems, payment processors, and government revenue collection mechanisms.

The implications of this leak extend beyond understanding the origins of specific cyberattacks. It provides concrete evidence of a systematic, institutional effort by the Russian military to train and integrate cyber operators into its intelligence apparatus. The presence of former Unit 26165 commander Viktor Netyksho within the training structure and correspondence bearing the signature of senior GRU officer Yuriy Shikolenko further bolsters the authenticity and significance of the findings. While the records do not directly tie every named individual to specific intrusions, they illuminate the human pipeline that fuels persistent Russian cyber campaigns.

For organizations, the practical takeaway is the reinforcement of robust, layered defenses rather than a reactive chase for new indicators of compromise. Security professionals are advised to patch internet-facing systems, restrict remote access, implement phishing-resistant multi-factor authentication, segment critical networks, and diligently monitor for unusual activity. This advice is particularly timely given the ongoing activities of APT28, which has been observed abusing edge routers, and Sandworm's increasing focus on industrial control systems.

Synthesized by Vypr AI