Leaked Russian Cyber-Operations Training Materials

This is interesting:

The records describe a force-generation mechanism for several General Staff components, including the GRU, Main Operational Directorate, and 8th Directorate, which is associated with protected communications, cryptography, and information security.

[…]

The reporting also linked a 2024 Department No. 4 graduate, Aleksei Kondrashov, to Military Unit 74455, widely known as Sandworm.

That unit has been associated with destructive cyber activity against Ukraine and other targets, including the 2017 NotPetya attack.

The reports do not establish that every listed graduate participated in a named operation; assignments should therefore be described as reported unit placements, not proof of individual operational involvement.

The Bauman material reframes Russia’s cyber capability as an institutional system, not merely a collection of well-known threat groups.

It suggests that Moscow has formalized a recurring pathway from university recruitment to military service, where students receive supervised technical and ideological preparation before entering intelligence, cyber, and security roles.

For defenders, the leak reinforces the need to track Russian operations as a combined threat: espionage, destructive activity, military reconnaissance, technical surveillance, and influence campaigns may draw on related personnel pipelines and overlapping doctrine.

The exposure of Department No. 4 also provides researchers with a clearer lens for understanding how the GRU sustains cyber capacity beyond the familiar APT28 and Sandworm brand names.

Posted on September 1, 2026 at 12:29 PM15 Comments

Comments

ResearcherZero September 1, 2026 8:59 PM

@Bruce

This kind of information about the training and its methodology, recruitment and organizational structure and the institutional approach of the GRU for each of its departments and individual units is know to the intelligence services.

The problem that exists is convincing law enforcement, government officials and elected representatives that all of the GRU activities are part of a larger operational focus with clear objectives which target specific places, people, industries, sensitive information and critical infrastructure. This includes blueprints for top secret defense projects, contractors, interdiction of communication systems of law enforcement, government records, medical and education records, classified reports, political candidates, government departments and agencies.

Anywhere information is stored, or can be extracted, is a potential target when GRU operatives are attempting to identify a specific person, family or resource. They will walk right in and take it from where it is stored in broad daylight and operate openly. For more secure locations they may employ more covert measures. Typically there is a lot of “noise” in their operations, often accompanied with what might appear as sporadic and random acts of violence. None of it is random. All of it is well planned and serves a specific purpose.

Undeclared GRU agents will try and convince someone with access to information to hand it over using an innocent sounding excuse, or talk someone into performing an action using deception. They will pose as government employees or law enforcement, or infiltrate their ranks. Threats, intimidation, enticement, deception and compromise are common tactics.

Recruitment of assets is typically performed through inducement. Money, promotion, access.
Intimidation and neutralization is performed using, guns, explosives, poisons and drugs.
The tools of reconnaissance will be deployed in preparation for, or execution of activities.

The likelihood anyone working in a government department or agency, or servicing public institutions, will recognize a colleague is a foreign agent is low. Training to identify rogue employees or insiders is practically non-existent in most government departments, industries and contractors. Suspicion is countered through deflection and simple lies.

Law enforcement lacks training, education, resources and dedicated teams to identify and tackle covert activity. They have no procedures or protocols to respond when they do. Lack of training and preparedness leaves a gaping hole in public safety and national security.

Lack of preparedness and support creates fear for those facing novel experiences. Frightened law enforcement officers are ineffective officers. Likewise, so are officials, defense contractors, or members of the public service working in any area of government.

ResearcherZero September 1, 2026 9:14 PM

As undeclared GRU officers behave like organized criminals they often pass as organized criminals (or members of the police force). They thrive in corrupt environments and are highly active, operating a relentless schedule, concurrently engaged in illicit activity.

Despite lacking diplomatic immunity, many of them have been in place for decades.

Clive Robinson September 1, 2026 11:40 PM

@ Bruce, ALL,

Be wary when you read,

“where students receive supervised technical and ideological preparation before entering intelligence, cyber, and security roles.”

The expression “ideological preparation” does not mean what many think it does as in the old “political officers” nonsense.

It is very much more along the lines of psychological selection for the ability to do acts without remorse or regret, but at a much higher intelligence level than that of a common thug or petty criminal.

Violence of a form few of us are capable of understanding is of use operationally as a “tool of the trade”.

Information can be extracted leaving few or no indicators then the person can be suicided or similar.

This has been going on for some years in the UK with both the UK Met Police and Home Office effectively “looking the other way”.

It appears that no mater how many times the Met were told “Murder not suicide” by the Russian community in London the official conclusion was suicide or death by misadventure…

The very few times it was very deliberately made “public” to send a message the Met and Home Office made it out to be “very special” not what it actually was.

The noise and palaver over the “Skripal assassination attempt” back in early 2018 is an example of this.

The poisoning of alleged former Russian spy Sergei Skripal and his daughter Yulia in Salisbury, England was not treated as what it was for so long by the local and later Met Police that much of the evidence and people involved were in effect “lost” to the investigation, and those who should have been brought in early were not brought in untill to late to be really of any use.

The use of the nerve agent involved was not for secrecy but to announce to Ex Russian’s in the UK that Putin could get them with impunity when ever he wanted to. The same with the earlier Polonium 210 killing of Alexander Litvinenko in 2006

And the “umbrella killing” on London Bridge of Bulgarian Georgi Markov in 1978.

These are just the ones that could not be hidden away by “bumbling police work”. And of course “political necessity” as much of the UK economy rested on Russian money flowing through “The City”.

There have been something like 30 suspicious deaths of Ex Russians in the past few years in the UK yet few ever got to hear of it… Except those for whom the messages are intended. Look up Nikolai Glushkov for instance and the timing of his demise.

Things are not much different in the US where “spy rings” are still very much up and running effectively in plain sight through the NRA and similar “establishment” organisations with direct connections to “folks on the Hill”. Similarly other FiveEyes countries.

But there are many other “accidental flying lessons” and the like where after extensive investigation it is found that those most likely to have caused the defenestration were in fact “freelancers” or similar who flew in and flew out again on the next plane and might not have been “in country” for more than a couple of hours. Often these are not political or state related murders but associated with Russian criminal Cartels.

But guess where such “freelancers” started and how they get their false almost perfect or even genuine false ID documents from…

ResearcherZero September 2, 2026 2:55 AM

@Clive Robinson

People have to be taught to blend in, act like the locals and know their customs. They cannot get too upset about perceived provocations against the Russian state, or they might blow their cover. The language and accent is they main thing they need to get right. Westerns are strange creatures and their society is perfectly organized for complete f’cking psychopaths who need to rise through the ranks, while enjoying a little midnight killing during their spare time and some illicit trade.

Laundering money and criminal enterprise are essential for raising funds, bribing or entrapping officials and creating the kind of environments where one can encourage compromising behaviour.

Unit 29155 recruited out of special forces and sometimes the Russian penal system (long before the invasion of Crimea). Of those selected, they looked for individuals with sociopathic tendencies with the ability to commit acts without remorse and maintain composure while they lied about it. People who murdered strangers or family members without provocation, then smiled and acted as if nothing had happened, or stated they were simply an innocent bystander who was attempting to offer assistance.

Candidates were put through the Spetsnaz training regime and those who completed it successfully were then selected for specific roles, based on their abilities. Some underwent further training for overseas deployment, much like the Illegals program, but with very different objectives. Unit 29155 also recruits locally in target countries. Murder and assassination of non-Russians is not covered in the media when it involves undeclared foreign agents and is rarely pursued by police. This allows GRU operatives to operate with impunity and without alerting those in the spaces and professions targeted.

There is a need for recruits with more modern skills and of a younger age – who talk the right lingo.
Today assets can be recruited by the internet for cheap, disposable missions and then discarded. But intelligence officers who are well trained are still needed to replace those who are burned or retire.

Given that the GRU has a deep interest in top secret blueprints for missile and naval technology, and that material they have stolen from FiveEyes has been used in Ukraine and by Russian nuclear forces, those nations should be paying a little more attention to GRU activities within their borders. Agents are permanently living in close proximity to naval bases where they have a clear view of movements of vessels in and out of those bases, and personnel who work at such facilities. Others are working inside government departments or have assets within government departments willing to assist them.

As you stated, these agents are cunning and they enjoy their work, especially violence. Other activities by resident GRU are more concerning, but land within the area that cannot be published.

If I had a check list to undermine the capabilities of a nation from within and compromise its institutions, so that nation could no longer properly protect itself or identify external threats, many have been achieved. Fortunately for the GRU, they do not have to do all that work for themselves.

The Army Secretary resigned after months of friction with Hesgeth. Being focused on modernization and military readiness, rather than the Trump administration’s fixation with culture wars, is not enough to keep servicemen out of Hesgeth’s crosshairs. Driscoll is among a number of losses of high ranking military officials to leave.

Recognizing allies and properly identifying foes, vulnerabilities and threats is a key leadership requirement.

https://edition.cnn.com/2026/08/31/politics/army-secretary-dan-driscoll-resigns

The departure of at least 20 top generals and military chiefs have created a leadership vacuum. Positions left vacant were overseeing modernization and readiness efforts. They have not been filed by permanent fixtures. It leaves the Department of Defense with temporary fixtures for key positions who cannot make permanent decisions.

A culture of fear within the armed forces and national security agencies hampers its effectiveness to detect activities below the level of active armed conflict and respond to covert external and domestic threats. It severely inhibits flows of critical information and intelligence from reaching and impacting decision-makers.

https://www.businessinsider.com/us-army-has-lost-top-figures-driving-transformation-2026-9

Ian Campbell September 2, 2026 7:27 AM

Good morning, folks!

While this was not my research, the GBHackers article was based off research from my team, DomainTools Investigations. You can find the original at:

https://dti.domaintools.com/research/threat-intelligence-report-university-leak-exposes-russias-military-cyber-training-pipeline

While it’s not a brand new dump, the original reporting/analysis focused on “hacker school” and Bauman is much more than that. To ResearcherZero’s early point, seeing the larger context on this one is critical for understanding operational interests and capabilities.

I hope it’s alright that I’ve posted this, seeing it come up on Dr. Schneier’s blog is a great honor. Please feel free to 86 it if this feels like too much self-promo, but I continue to be really proud of our scrappy little team.

If folks verifiably in a direct or adjacent field have further questions, please feel free to reach out.

Thank you!

r September 2, 2026 7:09 PM

you know, the initial pushback to hegseths opt-in testosterone levels check was probably not thought through.

the us military could probably find useable worthwhile information in the data it provides. but it’s going to take a long time for it to be properly borne out.

it’s kind’ve a nutritional signal, we just aren’t completely sure of it’s applicability yet.

i am fine with it being opt-in and not mandatory. he may get the opposite results he’s seeking from the data who knows.

if i’ve put my foot in my mouth again let me know, i’m not trained in population genetics or hormones or medical data sciences.

ResearcherZero September 2, 2026 9:39 PM

@Ian Campbell

This kind of research is fantastic for understanding the training, preparation and handling of agents and operations. It is rare that such information becomes publicly available and it would have once been a closely guarded secret that I doubt we would make known to any sitting ministers in government, even with a clearance.

It is very hard to convey the amount of planning that goes into covert operations and the serious ramifications of the objectives organizations like the GRU pursue. Connecting the separate, individual events that can be seen in the public sphere and on the ground, with the the teams directing the officers in the field and their actions, is critical for demonstrating that they are all parts of the same sausage.

All that is needed then is a good cook to serve up the sausage to the right people. Maybe we could test a few country singers and action movie stars with the clearance process, after auditioning them for presentation and communication skills. Those that pass might prove useful for presentations and government briefings. Hotdogs, flags and bunting, or more ominous settings using dark imagery of historical Soviet scenes and symbols.

I would like to see education programs rolled out to law enforcement to at least give them a little background on this stuff. Along with protocols and procedures on how to respond.

It has been a long time since I have been shot at. 😉

ResearcherZero September 3, 2026 7:58 AM

@r

When their are reorganizations within departments and changes in the senior staff, the replacements have not met the people that know the details relating to very important TS and SCI material. In compartmentalized settings, relationships and trust are built over time. Those who were not part of specific information loops and are transferred in from other areas or lower clearance levels, may not have had a working relationship with the same circles as their predecessor.

As different departments and agencies must liaise with one another to share information, it requires experience to learn who to talk to in order to get things done or find people who know what they are talking about.

One of biggest obstacles to the relay of vital information, is hopped up officials who believe they know everything, including the areas they know nothing about and have no actual experience or firsthand knowledge of working in those fields. These are the people who dismiss, without seeing the evidence for themselves, what they cannot understand or believe.

These failures of information sharing are sometimes called “Human Error” or “Intelligence Failures.” The root cause is arrogance, bureaucratic reorganization and ignorance due to a lack of communication skills or patience – and failures to follow processes and procedures.

A bigger problem emerges when people stop passing intel up the chain because the chief is a d–khead. Then all kinds of gaps and dysfunctions start to form in the gears of the system.

Once the central hub becomes a clusterf–k, the spokes on the wheel become disconnected.

Clive Robinson September 3, 2026 1:19 PM

@ Ian Campbell, ResearcherZero,

The thing to realise is that there are only so many ways “to skin a cat” when it comes to training entities with any kind of agency.

Once you recognise the brush strokes you see the process and thus the materials and importantly methods that go within.

There are two major limitations that are not being talked about currently but I’m fairly sure it won’t be long before they are. They effect both attackers and defenders and are about to go through a major transition.

The first is the traditional “up till now” issue that training chews up resources including time and thus makes the recipients of the process of increasing value as the training progresses.

The consequences of this is that,

“Things of value we tend to protect”

Where we can, thus this “cautionary behaviour” gets fed back into the early stages of the training process / pipeline and has effects all along.

Which has a knock on effect of what types of action can be considered for non special cases and even most special cases of action.

Knowing this can give some advantage to a defender as it makes attackers options more limited and thus predictable and negatable.

The second limitation is “entities with agency” which up to very recently has ment human entities even though we’ve had supposed “Smart / Precision Weapons” since before the 1980’s and arguably they started during WWII with the “proximity fuse” making artillery and similar “fires” way way more effective.

In essence adding sensors to agents gives new dimensions for attacks and defence to be considered in. Adding some kind of processing between sensor and guidance makes the weapon have some form of agency thus “Smarts”. Which makes attacks more effective and thus defence harder.

It also brings the cost of an action down considerably in easy to understand terms.

If a couple of pounds of smarts can make a 250lb smart iron bomb as effective or more so than a 1000lb dumb iron bomb. It significantly changes the attack calculus along with significantly increasing the defence cost and risk as defence has to switch from passive to active thereby making it’s presence more detectable by an attacker.

The game change is AI going between the sensor and the guidance and reaching the point where “Agency” is inexpensive and rapidly replaceable.

Thus it’s value in terms of training cost/time is in effect removed. Thus activities that were formerly not considered due to loss of agents with learned value is gone.

How long it will take for this to “work through” the operational and training pipelines is unknown but with a series of directly and indirectly active conflicts in progress we can expect to see weapons and systems with increasing amounts of “AI Agency” enter the domain and not just as augmented 5th Gen Smart Weapons.

ResearcherZero September 4, 2026 12:20 AM

@Clive Robinson

There are some important findings the investigators need to be aware of if they are to use their resources wisely, rather than waste them as a result of institutional biases.

Without identifying patterns of behavior and connections to other events, investigations fail. When dealing with events that result from foreign interference, law enforcement is likely to come across witnesses who have experienced traumatic and violent events.

Getting your leg blown off results in injury that is clearly visible. Other injuries may not be so visible or internal, yet can still cause a large amount of trauma. What cannot be clearly seen or might be overlooked can provide vital clues. This probably falls under the category of trauma informed policing, which is probably not the most appealing subject to law enforcement, as trauma/b> is a medical description of injury.

Identifying covert campaigns and connecting incidents to a larger orchestrated operation is hampered by how survivors and witnesses to incidents are treated. A small portion of the population (5%) account for the majority of victims (60%) impacted by all crimes. The way in which each eye witness is treated by law enforcement, directly impacts the evidence gathered and how officers proceed with investigation, or follow up incidents. If investigators dismiss the accounts of witnesses they run the risk of failing to identify key evidence and vital information that connects other events.

There are strong implications for how police and the courts perceive the reliability of witnesses. If officers disregard details relayed to them by witnesses, overlook evidence and dismiss other vital clues, it can send an investigation in the completely wrong direction. This leaves cases unresolved and increases the likelihood that police will fail to recognize that a string of repeated violent crimes or incidents are all connected.

‘https://academic.oup.com/bjc/advance-article/doi/10.1093/bjc/azag013/8504097

Police and Court Perceptions of Single-event and Repeat-event Witnesses

Although research finds that survivors of multiple violent incidents are demonstrated to deliver more credible testimonies and their descriptions of events are more accurate, it has also been found that the more times someone has survived violent incidents of crime, the less likely it is that they will be believed.

Repeated-event witnesses are perceived to be less honest and less credible than single-event witnesses, and less cognitively competent when delivering testimony.

https://www.theguardian.com/science/2026/sep/03/eureka-prize-2026-helen-paterson-jane-tiller-australian-science-prizes

ResearcherZero September 4, 2026 1:12 AM

@Clive Robinson

Currently the resources used by authorities are not used well to connect events together.
Even with the ability of AI to detect patterns and identify perpetrators, how individual officers respond, bureaucratic hurdles and institutional biases remain core obstacles.

The Russian military has a long history of very thorough study of the psychology of warfare and put that experience and knowledge into their operations. Repeated psychological and physical attack that results in long lasting impact, is a key component of the operational doctrine of both overt and covert Russian warfare and deployed in all operational spaces.

This includes the effects of trauma, which is a specific tactic used to keep campaigns off the radar of law enforcement, when engaging in malicious activity employed for espionage.
Repeatedly traumatizing victims and witnesses helps to undermine their credibility in the eyes of law enforcement, investigators and any further review of cases that takes place.

Violent actions will often take place in quick succession against targets, followed by pauses in activity, or other types of activity that disguise the connection with previous events. Operatives will move back and forth between groups of targets to break up the pattern of activity against individual targets, and the appearance of a larger campaign.

This approach helps to spread resources thin, so that investigative teams are not visiting each of the locations where events take place, to hamper the ability to make connections.

Lack of commonality of experience ensures anyone who makes the connection of a larger campaign will not be believed and that the accounts of witnesses sound too preposterous.

It exploits the weaknesses in the organizational structure of government agencies, so that each incident that takes place is more likely to be attended by different officers who have no knowledge of previous events, so that information is diffused and events kept separate.

Weather September 4, 2026 4:18 AM

@ResearchZero

Were did you learn that, talking to clive to much.

Russia has been given the green light, its not sig anymore more humit, they still have a lot of reserves if they want to op a notch, speak kindly.

ResearcherZero September 4, 2026 5:15 AM

@Weather, ALL

RE: Where did you learn that

Firsthand dealing with undeclared foreign agents, police and counter-intelligence. Also painfully over a long time while being shot, stabbed, tortured and poisoned, while the police repeatedly bungled investigations, arrests, or failed to follow up incidents and connect repeated acts of espionage with the accompanying acts of violence which facilitated the ability of the spies responsible to steal large amounts of classified material and kill people.

A lot of the violent incidents took place in public in front of dozens of eyewitnesses, yet police failed to land a single conviction. The individuals responsible made no attempt to disguise their identities while carrying out the crimes.

The group carrying out the espionage would identify material they wanted and then just toss it out of windows in boxes, where other members of the group could collect it. Many of the bribes were deposited directly into bank accounts, with the group transporting large piles of cash to those they paid off. The pilfered records from many government buildings.

It took only two weeks for me to identify how they laundered funds, the businesses they set up to do it and the shell companies they used. Simply by looking up their names in business registries and by observing their activities. It took federal police years to do that.

Eventually the police charged one individual, but for completely unrelated crimes. …

follow the dots

If law enforcement ranks are infiltrated, foreign agents (or those assisting them) can mislead colleagues or alter and destroy evidence. Police may come into contact with foreign spies far more often than they realize. They might be working alongside them.

‘https://warontherocks.com/the-cop-on-the-corner-is-our-first-line-of-defense-local-police-and-the-surveillance-detection-gap/

Even if you have the evidence, you may get fired for carrying out an investigation.

https://www.lawfaremedia.org/article/lawfare-daily–national-security–counterintelligence–and-counterespionage–a-guide-for-the-perplexed

Foreign intelligence services are increasingly targeting members of law enforcement.

Law enforcement faces a difficult task in separating criminal activity from foreign intelligence activity. It is easy for police to overlook violence as the result of crime or personal conflict, when it may instead be part of a much larger group of activities and incidents which are all planned and carried out by foreign agents.

Despite overlap, crime analysis and intelligence analysis have different goals and missions. The legal frameworks that counter-intelligence and law enforcement work within, are designed to separate the functions of intelligence organizations, from the actions and activities performed by law enforcement agencies.

While counter-intelligence and police do share information, differences in objectives and tasking prevent timely sharing of information and cooperation, that could help to fill in gaps in the knowledge of each organization.

As a large amount of information intelligence agencies hold is deemed classified, simpler forms of pertinent information that does not jeopardize national security can still be shared when classification is of concern.

Warnings about the level of danger that individuals present can assist law enforcement to better direct their focus. Counter-intelligence may not be able to share certain details, but they can help police to know when to follow up incidents and help connect other events and cases together. Police can likewise inform intelligence agencies about unusual activity or accounts from members of the public that may indicate espionage activities.

Identifying malign foreign activity is made much harder by police infiltration.
https://www.counterterrorismgroup.com/post/insider-threats-and-espionage-in-police-departments

ResearcherZero September 4, 2026 5:23 AM

@Weather

They pilfered records from many government buildings. Medical records from hospitals and other government buildings. Walked in. Walked the material to a room at the back of the building. Organized the records and packed them into separate boxes. Dropped out window.

The purpose of the violence was to intimidate as many people as possible and to encourage people to cooperate or stay quiet. This also worked on the police who sh-t themselves.

A lot of people in government departments rolled over or turned a blind eye.

Leave a comment

Blog moderation policy

Login

Allowed HTML <a href="URL"> • <em> <cite> <i> • <strong> <b> • <sub> <sup> • <ul> <ol> <li> • <blockquote> <pre> Markdown Extra syntax via https://michelf.ca/projects/php-markdown/extra/

Sidebar photo of Bruce Schneier by Joe MacInnis.