惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

月光博客
月光博客
MyScale Blog
MyScale Blog
博客园 - Franky
The Cloudflare Blog
IT之家
IT之家
Blog — PlanetScale
Blog — PlanetScale
博客园 - 聂微东
WordPress大学
WordPress大学
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
T
The Blog of Author Tim Ferriss
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
罗磊的独立博客
Google DeepMind News
Google DeepMind News
P
Proofpoint News Feed
Martin Fowler
Martin Fowler
aimingoo的专栏
aimingoo的专栏
J
Java Code Geeks
腾讯CDC
雷峰网
雷峰网
Microsoft Azure Blog
Microsoft Azure Blog
G
Google Developers Blog
博客园 - 【当耐特】
美团技术团队
云风的 BLOG
云风的 BLOG

Consumer Insights

The ransomware negotiator who was working for the other side After years on the run, alleged Ryuk ransomware operator pleads guilty INTERPOL crackdown shows scammers shifting to social media Meta lets strangers remix your public Instagram photos with AI—here’s how to opt out Invited to a "job interview" with Netflix or OpenAI? Beware! Your Google password could be at risk Two arrested over credit card phishing - as the Netherlands is named Europe's worst for payment fraud India pauses WhatsApp username feature over security concerns Alleged teen ransomware hustler faces US charges after arrest in Finland WhatsApp usernames explained: how to reserve yours and stay safe Scammers race to cash in on Venezuelan earthquake disaster USB drives carrying China-linked malware infected Japanese military networks for nearly a year WhatsApp tests new safety prompt before you chat with strangers Social media is worth celebrating. It's also worth protecting. Polish police dismantle SIM-swap gang accused of crypto theft Operation Endgame deals fresh blow to StealC and Amadey malware networks Hacker hijacks Brazil's national alert system, sending "misanthropy" to millions of phones Cybercrime now rivals traditional crime across parts of Asia Apple's Hide My Email tweak leaves privacy fans fuming Americans lost $3.5 billion to imposter scams last year — and the scams are getting harder to spot Scammers have killed the physical Steam Gift cards Crypto investment scam sends couriers to collect victims' cash, FBI warns Maine forced to take down data breach portal after fake notices filed with authorities Privacy own-goal: World Cup blunder leaks Lionel Messi's passport details Why schools remain one of cybercriminals' favourite targets WhatsApp detects new spyware activity from Israel’s NSO Group despite court order Got a LinkedIn message from a recruiter? It might be Chinese intelligence, warn FBI and MI5 Europol cracks down on illegal streaming globally Hackers didn't hack Instagram; they just asked Meta AI FBI Warns Fans About FIFA Scams Ahead of 2026 World Cup Virtual knife, real lawsuit: Counter-Strike skin dispute ends in court
Inside Department 4: Russia's secret school for hackers
Graham CLULEY · 2026-05-08 · via Consumer Insights

Most universities have a careers fair. At Bauman Moscow State Technical University, however, an elite group of students appear to have something rather more unusual: a direct pipeline into some of the world's most notorious state-sponsored hacking groups.

A new investigation by a consortium of journalists from The Guardian, Der Spiegel, Le Monde, and The Insider, amongst others, has lifted the lid on a secretive faculty inside one of Russia's most prestigious technical universities - that has spent years grooming students to become hackers for Russian military intelligence.

Reporters managed to obtain a haul of 2,000 internal documents which revealed some of the secret goings-on, including at "Department 4" - a faculty with a seemingly deliberately unmemorable name within Bauman's military training centre, where the GRU appears to go shopping for fresh talent.

Russia's military intelligence service, the GRU, directly controls who gets into Department 4, according to the leak. It is GRU that is overseeing exams, and signing-off on graduates' postings, with some promising students scouted as early as secondary school.

A core course called "Defence against technical reconnaissance" covers password attacks, software vulnerabilities, and trojan horses. Students are told to carry out practical penetration tests, and one module is devoted entirely to computer viruses, with students required to write a virus of their own as part of the assessment. Presumably they gain extra marks for not infecting their lecturer's laptop.

In addition, there are lessons in old fashioned James Bond-style spying with surveillance devices disguised as smoke detectors, physical keyloggers, and cables that silently send screenshots to a hidden drive.

Among the 69 students who reportedly graduated from Department 4 in 2024 was Daniil Porshin. He spent six years at Bauman, achieving near-perfect grades. Upon his graduation, he is said to have been assigned to the Fancy Bear hacking group, which was linked by the US Department of Justice over the high profile hack of the Democratic National Committee.

Fifteen other students found themselves assigned to hacking gangs, including one who appears to have been assigned to Unit 74455 (better known as Sandworm) - the GRU group which has been blamed by Western governments for attacks on Ukraine's power grid, Emmanuel Macron's 2017 presidential campaign, and the 2018 Winter Olympics.

It is worth noting that not everyone makes the grade, with one student assessed by a senior GRU officer to have "insufficient understanding of how to carry out a remote network attack."

According to the documents, one of Department 4's teachers is Major General Viktor Netyksho. If that name is familiar to you, it may be because he was indicted by Robert Mueller over the DNC breach. He has, it seems, gone from running the Fancy Bear hacking group to helping train its replacements.

What the report does is act as a useful reminder that the threat posed by groups like Fancy Bear and Sandworm is serious and organised. Russia is running a state-funded, state-directed production line for hackers - complete with lecture theatres, examination boards, and a steady supply of fresh recruits.

All of this means that those responsible for securing their organisations from cybercriminals cannot afford to relax.

Patch your systems, enable multi-factor authentication, segment your network, log activity, train your workforce, make regular backups, run penetration tests against your organisation to see where your weak points may be, and so forth.

Determined GRU-trained hackers, hell-bent on breaking into your organisation's IT infrastructure, may still find it impossible to find a way in - but make sure you have done everything in your power to make it as difficult for them as possible, and limit any damage they might be able to cause.