August has come and gone, and my team and I have finally recovered from the excessive Las Vegas heat we had to endure during Hacker Summer Camp. However, August ending in Seattle also means we have roughly only six more weeks before the sun takes a break from the Pacific Northwest, and the eternal gray sets in until next April. And let’s be real, that six week estimation is a generous one - Take your vitamin D supplements, people! While the sun may be setting earlier, the threats have been shining plenty bright to keep my team busy.
Today, let’s start with what we published at the end of the month: My team got ahold of leaked internal documents from Bauman Moscow State Technical University, and we spent a good chunk of August combing through the files. We published the findings from our analysis of the leak, and it is one heck of an investigation. Most public reporting covered the GRU Hacker School aspect of the leak, but the documents revealed so much more.
We also published part five of our series tracking a “super-cluster” of malware delivery domains linked to the Silver Fox threat actor group that’s targeting Chinese-speaking users. If you haven’t been following this investigation so far, we’ve been tracking this cluster since January 2025, Late last year we published Part 4 of the series, which included our agentic-AI powered security analysis. Finally, we started the month with a bite-sized investigation into markets for stolen and fraudulent accounts.
Now, let's dive in (reverse) and get you up to speed!
Hot Off the Presses
Threat Intelligence Report: University Leak Exposes Russia’s Military Cyber Training Pipeline
To close out August, the DTI team reviewed the leaked internal documents from Bauman Moscow State Technical University’s Department No. 4. While public reporting focused on the “GRU Hacker School” angle, our researchers took a deep dive into the documents to analyze the curriculum, training groups, personnel and assignments, and training materials included in the leak. Most reporting focused on only one of the three training groups revealed in the leak, the Special Intelligence Service group, because it provided the clearest link to military intelligence. However, two other groups focused on cyber operational effects and secure communications and technologies. Our research covered the curriculum and training for all three groups, as well as an underreported financial systems program included in the training for the Special Intelligence Services group.
The research also covered a malware-analysis and cyber threat intelligence program, including a 2023 Bauman Military Training Center conference volume: “Current Issues Concerning the State and Prospects for the Development of Weapons, Military, and Special Equipment of the Aerospace Forces”.

Chinese Malware Delivery Domains Part V
In Part V of our series investigating a domain super-cluster tied to the Silver Fox threat actor group, our researchers analyzed continued activity around the cluster despite arrests by Chinese authorities of individuals associated with Silver Fox. In Part IV of the series, our researchers proposed the hypothesis that the malware delivery "super-cluster" operates as a decentralized Malware-as-a-Service (MaaS) platform. In Part V, we identify three distinct operational profiles that continued active following the arrests and break down the variations across the infrastructure and lures associated with the cluster.
Our team also analyzed samples from this recent activity cluster that all point to an obfuscated variant of Gh0stRAT. Despite variations in the initial lures used, for the samples reviewed in this campaign, the technical execution chain, obfuscation methods, and final payload structure are nearly identical.

Read Part V of the series here
SecuritySnack - Account Farmers and Sellers
To kick off August, my team published a security snack on fraudulent account reseller markets. The push for user-base growth by major email providers is often paired with minimal fraud prevention, shielded from legal consequences with boilerplate disclaimers in the SEC filings. This means actors can easily create fraudulent emails that subsequently serve as the gateway for spam, malicious infrastructure, bot networks and fraudulent accounts across all manner of other services. Our investigation surveyed some of the most recent sites alleging to sell such accounts.

What We’re Reading
In case you’re behind on your cybersecurity reading homework, DTI team member Ian Campbell’s monthly recommended reading list has returned and will get you up to speed!
- The top article for the month: Gambit Security Threat Intel - AI Across the Intrusion Lifecycle
- The top research for the month: arXiv - Signals in the Noise: Open Source Intelligence (OSINT) for AI Loss of Control Detection
- The top tool for the month: Jarocki - Pivotglass
📚See the full reading list here
Where We’ll Be
- BSides NoVa, Arlington, VA, 30-31 October
Final Thoughts
As always, thank you to my returning readers! If you’re new, I hope you found this newsletter informational, helpful, and worthy of sharing with your peers. And of course I hope you will be coming back to read future editions!
We share this newsletter via email as well - if you’d prefer to get it to your inbox, sign up here.
If you missed last month's content, here are some quick links:
- Threat Intelligence Report: The Pro-Iran Hacktivist Ecosystem 2026
- Scarcity Scams
- Intelligence Report: The Zedxion Corporate Nexus for Illicit Iranian Financial Funds Transfer for IRGC Entities
Thanks for reading & see you next month!
-Daniel
https://www.linkedin.com/in/schwalbe/
https://infosec.exchange/@danonsecurity


















