Security3 distinct publishers3 min readPublished Updated
A media consortium and DomainTools worked through more than 2,000 records from a Moscow engineering department that appears on no public org chart, and found roughly 250 students on a documented path into Russian military intelligence.
The Watch · Security desk
Compiled by The WatchSomething wrong?How this is made
The staffing numbers are worth walking through first. Roughly 250 career and reserve students passed through Department No. 4 over six academic years [7], which averages about 42 per intake [1]. Researchers estimate that 10 to 15 students each year were selected for GRU-related assignments before graduating [8], so 60 to 90 people across the six years, between a quarter and a third of everyone who went through [2]. Those are staffing numbers, and they hold across six consecutive cohorts.
The curriculum tells you what the graduates were built to do. Course materials define "information-technical weapons" as tools and methods designed to alter, destroy, copy, block, or manipulate information [9]. Red-team and blue-team functions are taught as one discipline rather than two tracks [10]. Technical protection instruction covered cryptography and steganography, code analysis and intrusion detection, hardware inspection, the discovery of physical implants, and the identification of undocumented device functions [11]. DomainTools also flags a malware-analysis and threat intelligence program in the files that had not previously been reported [12]. One advanced practical assignment required a social-media video built around what the materials called "manipulation, pressure, and hidden propaganda" [13]. It counted as coursework.
Provenance deserves separating from content. The records run through 2025 and cover academic and administrative material [2]. A DarkForums user known as "Losyash" may have shared the data, and it has not been confirmed that the account obtained it in the first place [14]. What holds the reading up is that two sets of eyes worked the same corpus: the consortium of The Insider, The Guardian, Le Monde, Der Spiegel, Delfi, VSquare and FRONTSTORY.PL [3], and DomainTools researchers analysing the files independently [4].
None of this changes a patch queue: the files carry no indicators and no new vulnerability, but what they do change is the resolution of attribution. Unit staffing has generally been inferred from tooling and tradecraft overlap; here there is a department inside Bauman's Military Training Center that does not appear on the university's public org chart [5], dated cohorts, and at least one named individual. Reporting places graduates in Military Unit 26165, associated with APT28 [15], and Unit 74455, associated with Sandworm [15], and identifies Aleksei Kondrashov, a 2024 graduate, as linked to 74455 [16]. Major General Viktor Netyksho sits in the department's teaching and oversight structure, having commanded Unit 26165 and the 85th Main Special Service Center [17]. He was one of 12 GRU officers indicted in the United States in 2018 over interference in the 2016 presidential election [18].
Put together, the finding takes a clear shape. A unit whose operators have been tracked as Fancy Bear, Sofacy and STRONTIUM for a decade [19] draws from an accredited engineering faculty with a known intake rate, known instructors, and a syllabus that trains intrusion and influence work side by side [20]. Planning assumptions about attrition, burn rates from sanctions and indictments, and how fast these units regenerate capability now have a number attached to them.
Ranked by verification strength, evidence, and original report placement.
Department No. 4 served several elements of the Russian General Staff and trained students across three specialties: special intelligence, operational information-technical effects, and information-technology protection.
Aleksei Kondrashov, a 2024 Department No. 4 graduate, is identified as linked to Military Unit 74455, the GRU's Main Centre for Special Technologies.
DomainTools researchers analyzed the leaked files independently of the media consortium.
Reporting identified graduates assigned to GRU Military Unit 26165, associated with APT28, and Military Unit 74455, associated with Sandworm.
Military Unit 26165 is the GRU formation publicly associated with APT28, also tracked as Fancy Bear, Sofacy and STRONTIUM.
More than 2,000 internal documents from Bauman Moscow State Technical University have been reviewed by an international media consortium.
Distinct publishers with included, body-backed reporting in this cluster.
1 article · September 1, 2026
1 article · September 2, 2026
1 article · September 3, 2026
Follow any of these and your For You feed starts watching them — no settings page required.
security
994 dossiers in 499 pages: the NoName057(16) file reads as collection, not defacement1 distinct publisher
security
FBI names Nanjing contractor behind 300-victim Check Point Quantum Gateway campaign1 distinct publisher
security
UAC-0099 buried a nuclear weapons prompt in a VBS dropper to stall AI-assisted triage2 distinct publishers
build
Europe's arms plants are burning, and the arsonists are being hired locally1 distinct publisher
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
One corpus, one analysis, three retellings
Trace any specific here and it lands in the same place: DomainTools' read of a single leaked document set, quoted at length by Security Affairs and excerpted by Schneier. The consortium that did the parallel document work is named but never quoted in our coverage, so the cross-check a reader assumes exists is not visible. Two things raise this above thin: the records are internal and numerous rather than anecdotal, and the Kondrashov placement appears in all three accounts. Two things hold it down: the 10-to-15-a-year selection figure is an estimate, not a count, and how the files were obtained is openly unresolved.
Six intakes documented, placements thin
As institutional throughput this is real and durable: roughly 250 career and reserve students across six academic years, about 42 an intake, taught by a department that never appears on the university's public chart. Where it thins out is the exit. Two people are actually named — Kondrashov into Unit 74455, Netyksho in the oversight chain — while the 60-to-90 GRU-assigned graduates come from multiplying an estimate. The pipeline's existence is documented; the volume flowing out of it is modelled.
Headlines run ahead of the bodies
The headline promise — a factory that turns engineering students into GRU cyber operators — is bigger than the arithmetic underneath it, which rests on an estimated selection rate and files whose origin nobody has confirmed. But the bodies are unusually disciplined for a leak story: Security Affairs calls the placements 'not individual operational involvement,' and Schneier makes the same point unprompted. The gap that remains opens up at the aggregation step, where SC World forwards the conclusion and leaves both hedges behind.
Vendor research, relayed twice
DomainTools sells threat intelligence, and a leaked GRU training file set is an excellent showcase for the craft it sells; that is not a reason to doubt the work, but it does explain why the analysis is public and why it is framed as a lens for defenders. The relay chain compounds the effect — Schneier excerpts, SC World summarizes Schneier, Security Affairs quotes the report in bulk — and none of the three has any incentive or apparent means to re-examine the documents. No affected party is heard from: no response from Bauman, none from the named officers.
Coherent and careful, singly sourced
What the documents describe hangs together: a hidden department inside a military training center, three named specialties, a doctrine-consistent merger of offense and defense, senior officers grading students. Nothing in it strains belief and the reporting flags its own limits. The ceiling is structural rather than editorial — one leaked corpus of unconfirmed origin, one analytical team, no independent replication visible in our coverage, and no comment from anyone named in the files.