DOMAINTOOLS’ September 17, 2026 newsletter highlights research into leaked internal documents from Bauman Moscow State Technical University’s Department No. 4. The documents reportedly describe three training groups: one focused on special intelligence services, another on cyber operational effects, and a third on secure communications and technologies. DomainTools also identified an underreported financial-systems programme, alongside training in malware analysis and cyber threat intelligence. The findings are based on the leaked material and expand beyond public reporting that concentrated on the so-called “GRU Hacker School”.
The newsletter also reports continued activity in a malware-delivery domain “super-cluster” associated with the Silver Fox threat actor group, despite arrests by Chinese authorities of people linked to the group. DomainTools says its latest analysis identified three operational profiles and supports a previous hypothesis that the infrastructure may function as a decentralised malware-as-a-service platform. Samples from the activity were assessed as obfuscated variants of Gh0stRAT.
Although the initial lures varied, the reviewed samples reportedly shared nearly identical execution chains, obfuscation methods and final payload structures. The activity is described as targeting Chinese-speaking users; the newsletter does not state that the arrests or campaign activity resulted in confirmed victim numbers.
A separate investigation examined markets advertising fraudulent or stolen online accounts. DomainTools said weak fraud prevention at major email providers can enable the creation of fake email accounts that are later used for spam, malicious infrastructure, botnets and fraudulent accounts on other services. The research surveyed websites claiming to sell such accounts, but the newsletter provides no confirmed assessment of the sellers’ reliability or the scale of the market.