Security1 distinct publisher3 min readPublished
A media consortium and DomainTools worked through more than 2,000 records from a Moscow engineering department that appears on no public org chart, and found roughly 250 students on a documented path into Russian military intelligence.
The Watch · Security desk
Compiled by The WatchSomething wrong?How this is made
The staffing numbers are worth walking through first. Roughly 250 career and reserve students passed through Department No. 4 over six academic years [7], which averages about 42 per intake [1]. Researchers estimate that 10 to 15 students each year were selected for GRU-related assignments before graduating [8], so 60 to 90 people across the six years, between a quarter and a third of everyone who went through [2]. Those are staffing numbers, and they hold across six consecutive cohorts.
The curriculum tells you what the graduates were built to do. Course materials define "information-technical weapons" as tools and methods designed to alter, destroy, copy, block, or manipulate information [9]. Red-team and blue-team functions are taught as one discipline rather than two tracks [10]. Technical protection instruction covered cryptography and steganography, code analysis and intrusion detection, hardware inspection, the discovery of physical implants, and the identification of undocumented device functions [11]. DomainTools also flags a malware-analysis and threat intelligence program in the files that had not previously been reported [12]. One advanced practical assignment required a social-media video built around what the materials called "manipulation, pressure, and hidden propaganda" [13]. It counted as coursework.
Provenance deserves separating from content. The records run through 2025 and cover academic and administrative material [2]. A DarkForums user known as "Losyash" may have shared the data, and it has not been confirmed that the account obtained it in the first place [14]. What holds the reading up is that two sets of eyes worked the same corpus: the consortium of The Insider, The Guardian, Le Monde, Der Spiegel, Delfi, VSquare and FRONTSTORY.PL [3], and DomainTools researchers analysing the files independently [4].
None of this changes a patch queue: the files carry no indicators and no new vulnerability, but what they do change is the resolution of attribution. Unit staffing has generally been inferred from tooling and tradecraft overlap; here there is a department inside Bauman's Military Training Center that does not appear on the university's public org chart [5], dated cohorts, and at least one named individual. Reporting places graduates in Military Unit 26165, associated with APT28 [15], and Unit 74455, associated with Sandworm [15], and identifies Aleksei Kondrashov, a 2024 graduate, as linked to 74455 [16]. Major General Viktor Netyksho sits in the department's teaching and oversight structure, having commanded Unit 26165 and the 85th Main Special Service Center [17]. He was one of 12 GRU officers indicted in the United States in 2018 over interference in the 2016 presidential election [18].
Put together, the finding takes a clear shape. A unit whose operators have been tracked as Fancy Bear, Sofacy and STRONTIUM for a decade [19] draws from an accredited engineering faculty with a known intake rate, known instructors, and a syllabus that trains intrusion and influence work side by side [20]. Planning assumptions about attrition, burn rates from sanctions and indictments, and how fast these units regenerate capability now have a number attached to them.
Ranked by verification strength, evidence, and original report placement.
Reporting identified graduates assigned to GRU Military Unit 26165, associated with APT28, and Military Unit 74455, associated with Sandworm.
More than 2,000 internal documents from Bauman Moscow State Technical University have been reviewed by an international media consortium.
The leaked files span academic and administrative records through 2025.
The investigation was carried out by a group of media outlets including The Insider, The Guardian, Le Monde, Der Spiegel, Delfi, VSquare and FRONTSTORY.PL.
DomainTools researchers analyzed the leaked files independently of the media consortium.
Department No. 4, also called "Special Training," operated inside Bauman's Military Training Center and does not appear anywhere on the university's public organizational chart.
Distinct publishers with included, body-backed reporting in this cluster.
1 article · September 3, 2026
Follow any of these and your For You feed starts watching them — no settings page required.
security
994 dossiers in 499 pages: the NoName057(16) file reads as collection, not defacement1 distinct publisher
security
Nearly four in ten breached German companies now name a foreign intelligence service1 distinct publisher
security
UAC-0099 buried a nuclear weapons prompt in a VBS dropper to stall AI-assisted triage2 distinct publishers
build
Europe's arms plants are burning, and the arsonists are being hired locally1 distinct publisher
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
One retelling of one vendor's read
Every figure in this story — 2,000 documents, 250 students, ten to fifteen a year — reaches us through Security Affairs quoting DomainTools quoting paperwork no one in our coverage has examined. The consortium partners are named as citations, not sources. What keeps this from being a bare vendor blog is that its anchors are checkable elsewhere: Netyksho's 2018 indictment and the Unit 26165/APT28 mapping are public record and do not depend on the leak being genuine.
No downstream response visible
We cannot measure what anyone did with this. No university or government reply, no sanctions or charges, no detection guidance, no second party acting on the findings. DomainTools recommends tracking Russian operations as one combined threat, but a recommendation is not uptake, and our coverage stops before anyone takes it up.
Disciplined caveat, confident numbers
The overreach is modest and mostly in the framing. Security Affairs earns real credit for saying outright that a posting to Unit 74455 does not put a person at NotPetya — the sort of line that usually goes missing. But "the factory behind the names" and "visible for the first time at this level of institutional detail" claim more than one read of leaked coursework can settle, and the estimated ten-to-fifteen selections a year hardens into a headline statistic on the way through.
Research that argues for the product
DomainTools sells threat intelligence, and its conclusion — stop separating Russian espionage, sabotage and influence work, track the pipeline — is a case for precisely the analysis it markets. That does not make it wrong; it does mean the framing arrives pre-shaped. Two further interests go unweighed: a consortium with a scoop to protect, and whoever pushed 2,000 wartime documents onto a criminal forum in the first place, whose motives the reporting never asks about.
Plausible shape, thin corroboration
The picture fits everything already known about how Russian military cyber units are staffed, and its named anchors survive outside the leak. Against that: one publisher, one vendor analysis, no adversarial check on the documents, no comment from anyone with a reason to dispute them, and the sharpest numbers estimated rather than counted. Enough to brief on; not enough to build an accusation on.