Recently uncovered records from a Russian university have shed light on the structured training pipeline feeding into the GRU’s cyber units, specifically those associated with APT28 and Sandworm. These groups have been linked to various cyber activities including espionage, credential theft, and disruptive operations targeting governments and critical infrastructure.
Details of the Leaked Records
The leaked documents reveal a comprehensive training program that combines classroom instruction, hands-on exercises, and supervised military placements. This program is believed to cultivate the skills necessary for the persistent cyber campaigns conducted by Russian military-linked groups.
The records, examined by DomainTools Investigations, do not point to new victim campaigns or malware but instead offer insight into the development of technical skills, operational planning, and intelligence capabilities. This training program’s existence helps explain the enduring and varied cyber activities linked to Russia’s military.
Inside Bauman Moscow State University
The leaked archive is from Department No. 4 in Bauman Moscow State Technical University’s Military Training Center. It includes personnel lists, schedules, exams, and placement records detailing the recruitment and training of students. Around 1,600 files reportedly document the paths of approximately 250 career and reserve students.
The program focuses on three main specialties: Special Intelligence Service, information-technical effects and protection, and information-technology protection. The largest group, information-effects, had about 120 students in 2024, indicating a robust training model.
Implications and Recommendations
The curriculum covers a range of topics including password attacks, server exploitation, vulnerability research, and malware creation. Such a comprehensive training approach ensures trainees are well-versed in both offensive and defensive cyber operations.
Field placements further enhance this training, with students gaining practical experience at various locations across Russia. The leak also highlights a financial systems security path within the special-intelligence stream, which can be used to assess vulnerabilities in financial and government systems.
Organizations are advised to strengthen their defenses by patching systems, restricting remote access, and implementing multifactor authentication. This proactive approach is crucial as groups like APT28 and Sandworm continue to evolve their tactics.
Overall, the leaked records suggest that Department No. 4 plays a critical role in preparing cyber operators for Russia’s General Staff. While the source of the archive remains unknown, its insights are invaluable for global security teams.
