A newly surfaced cache of internal records from Bauman Moscow State Technical University’s secretive Department No. 4 appears to map a formal training pipeline that feeds cyber operators and intelligence officers directly into Russia’s military intelligence directorate, the GRU[1][2][11]. The leaked files, totaling around 2,000 documents and spanning activity up to 2025, include student rosters, curricula, and assignment records that link graduates to high-profile GRU cyber units associated with the threat groups APT28 and Sandworm[2][4][8][11].
According to investigations by multiple media outlets and threat intelligence researchers, Department No. 4 operates as a hidden faculty within Bauman’s Military Training Center, sitting alongside conventional engineering programs while training a smaller cohort of roughly 250 career and reserve students[1][2][6][11]. The material describes three main military specializations: a “Special Intelligence Service” stream focused on electronic reconnaissance and information warfare, an “Information Technology Security” track, and a discipline covering “Deployment and Defense Against Information and Technical Means of Influence,” all explicitly linked to various directorates of the Russian General Staff, including the GRU and the 8th Directorate responsible for protected communications and cryptography[2][4][6]. The records indicate that the GRU itself oversees admissions, examinations, and graduate postings, reinforcing that this is not a civilian cybersecurity program but an embedded military training system[3][4][7][12].
Threat intelligence reporting on the leak connects Department No. 4 graduates to GRU Military Unit 26165, widely associated with the APT28 espionage-focused threat group, and to Military Unit 74455, the destructive operations unit more commonly known as Sandworm[1][9][12]. Unit 74455 has previously been tied by Western governments and security researchers to major incidents including the 2015 Ukraine power grid compromise, the 2017 NotPetya wiper outbreak that caused worldwide disruption, interference efforts targeting the 2017 French presidential election, and the 2018 OlympicDestroyer attack on the PyeongChang Winter Olympics[10][13][14][15]. While some leaked records reportedly name individual graduates and their unit placements, the documents do not by themselves prove that every listed officer participated in specific operations, and researchers caution that these postings should be treated as reported assignments rather than definitive evidence of personal involvement[1][12].
The leaked Bauman files show that Russia’s cyber capability is being cultivated as an institutional system with a recurring pathway from early recruitment through university-level training to service in intelligence and military cyber units, rather than as a loose constellation of standalone threat groups[1][3][9][12]. Reporting indicates that promising candidates may be identified as early as secondary school, then funneled into Department No. 4 where they receive supervised technical preparation alongside ideological conditioning before entering roles in espionage, offensive cyber operations, information warfare, and defensive security[3][4][7][12]. Course materials and syllabi cited in the leak include topics such as penetration testing, spearphishing campaigns, malware development, financial-system targeting, reconnaissance, technical surveillance, and cryptographic defense, suggesting a broad curriculum that mirrors the toolsets used in recent GRU-attributed operations[1][2][12].
For defenders, the exposure of Department No. 4 underscores that Russian cyber activity should be tracked as a combined threat drawing on shared personnel pipelines and overlapping doctrine, rather than siloed into brand names like APT28 and Sandworm[1][9][12]. Intelligence, destructive attacks, military reconnaissance, technical surveillance, and influence campaigns may all be executed by officers who passed through the same training program and who rotate between units across their careers, complicating attribution and increasing the likelihood of cross-domain tradecraft reuse[3][9][15]. The Bauman leak gives incident responders and analysts a clearer lens into how the GRU sustains cyber capacity at scale, offering new context for correlating campaigns, understanding long-term operator development, and anticipating how future operations might blend espionage and disruption against both Ukrainian and global targets[1][12][13].
References
- University Leak Exposes Russia’s Military Cyber Training …
- Inside Bauman University’s Department 4, an elite spy school …
- Inside Department 4: Russia’s secret school for hackers
- Welcome to the GRU University, Where Moscow Turns …
- Leaked Documents Expose Secret Intelligence Faculty at …
- Leaked University Files Reveal How Russia Trains Hackers for Military Cyber Operations
- Secret Russian spy school dubbed ‘Hogwarts for hackers’ is revealed with chilling link to deadly Salisbury attacks
- Research – DomainTools Investigations
- US Indicts Sandworm, Russia’s Most Destructive Cyberwar Unit
- Bauman Moscow State Technical University – Wikipedia
- Dark Web Scanner: Russia’s University Cyber Training Leak
- Sandworm (hacker group)
- US charges Russian hackers behind NotPetya, KillDisk, OlympicDestroyer attacks
- Sandworm: A tale of disruption told anew – WeLiveSecurity








