Leaked internal records from Bauman Moscow State Technical University reportedly reveal that its Department No. 4 operated as a concealed military-training program feeding personnel into Russian General Staff, intelligence, cyber, and security organizations. The program, housed in the university’s Military Training Center, reportedly provided supervised technical and ideological preparation under three military specialties before placing selected graduates in roles involving offensive cyber operations, information warfare, technical reconnaissance, and defensive security.
The reported curriculum included vulnerability exploitation, password attacks, spearphishing, Trojan and malware development, DDoS attacks, penetration testing, electronic reconnaissance, propaganda, and psychological manipulation. The files describe oversight and placement links to GRU-associated Military Units 26165 and 74455, publicly linked to APT28 and Sandworm/APT44, respectively; reporting also linked a 2024 graduate, Aleksei Kondrashov, to Unit 74455, though the material does not establish that he or other named graduates took part in specific operations.

TTPs, infrastructure, and targeting history in one profile.
5 events from the most recent confirmed update back to the earliest known activity.
Reporting linked 2024 Department No. 4 graduate Aleksei Kondrashov to a placement at GRU Military Unit 74455, commonly known as Sandworm. The reporting does not establish his participation in a specific cyber operation.
The United States indicted Viktor Netyksho and 11 other GRU officers in connection with interference in the 2016 U.S. presidential election.
Sandworm, also associated with GRU Military Unit 74455, has been linked in reporting to the 2017 NotPetya attack.
Reporting states that Major General Viktor Netyksho and other GRU officers were connected to interference in the 2016 U.S. presidential election.
A leaked archive of internal Bauman Moscow State Technical University records reportedly exposed Department No. 4, a concealed program that trained and placed students into Russian General Staff, intelligence, cyber, reconnaissance, and information-warfare roles. The archive reportedly includes curricula, examinations, staffing, graduate, and placement records through 2025.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
7 references tracked. Mallory keeps watching after this page renders.
securityaffairs.com
Open sourcescworld.com
Open sourcegbhackers.com
Open sourceschneier.com
Open sourcecyberveille.ch
Open sourcedti.domaintools.com
Open sourcecongress.gov
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.