← Back to feed
PhishingEmerging1 sourceAug 28, 2026 · 10:48via Cyber Security News

Russian University Leak Exposes GRU Cyber Training Pipeline Behind APT28 and Sandworm

Brief

Leaked university records have opened an unusual window into Russia’s military cyber ecosystem. The documents point to a structured training program, not a newly discovered piece of malware, that appears to feed people into GRU units associated with APT28 and Sandworm.

The finding matters because these groups have been linked to espionage, credential theft, sabotage, and disruptive operations against governments and vital services.

Their documented approaches include phishing, stolen credentials, and the exploitation of exposed systems, so the leak has relevance far beyond Russia.

Analysts at DomainTools Investigations examined the material and found a program joining classroom instruction, attacker-versus-defender exercises, and supervised military placements. It offers rare detail on the human pipeline behind enduring campaigns.

Read more on Cyber Security News