What are the core benefits of Kaspersky APT & Crimeware & Industrial Intelligence Reporting?
Portal access – read online via Kaspersky Threat Intelligence Portal.
Three streams – APT, crimeware and ICS reports combined.
Machine readable – IoCs, YARA and Suricata rules per report.
Actor mapping – TTPs mapped to MITRE ATT&CK techniques.
Private research – includes investigations that are never published.
Important note – intelligence only, it detects and blocks nothing.
APT Intelligence Reporting – Analysis of targeted campaigns as Kaspersky identifies them.
Crimeware Intelligence Reporting – Financially motivated attacks on banks and payment infrastructure.
ICS Intelligence Reporting – Campaigns and vulnerabilities affecting industrial control system environments.
Machine readable indicators – IoCs, YARA rules and Suricata rules per report.
Threat Intelligence Portal – Browser access with inline charts and geographic filtering.
Important – No agent, no console, no detection and no blocking function.
This is a subscription research service that bundles three report streams Kaspersky also sells individually, among them Kaspersky APT Intelligence Reporting. It uses no agent and no management console: analysts open, filter and download the reports through the Kaspersky Threat Intelligence Portal in a browser.
Non-public investigations – Includes research that never appears on public blogs.
Detection rules included – YARA and Suricata rules load straight into existing tooling.
ATT&CK mapped TTPs – Shows which techniques your current controls already cover.
Industrial vulnerability analysis – Control system flaws rated by real exploitation relevance.
Filtered by relevance – Geographic and sector filters cut reading time per report.
Sustained output – Kaspersky states over 200 reports are released annually.
The deciding factor is not headcount but whether someone in the organisation reads threat reports as part of their job. A company without a SOC, a SIEM or a dedicated security analyst has nowhere to put IoCs and YARA rules, and the subscription stays unused.
| Requirement | Small business | Medium-sized company | Large company |
|---|---|---|---|
| Reporting obligation Switzerland | Rarely | By sector | By sector |
| NIS 2 in the European Union | Rarely | By sector | ✓ |
| Security questionnaire from large customers | Sometimes | ✓ | ✓ |
| Analysts able to act on IoCs and YARA rules | ✕ | Rarely | ✓ |
| This product fits | ✕ | Limited | ✓ |
No, and no software does. The revised Information Security Act obliges operators of critical infrastructure in Switzerland to report cyberattacks to the Federal Office for Cybersecurity (BACS) within 24 hours of discovery, and that duty sits with the organisation, not with a purchased product. Where this service helps is the content of such a report: APT and ICS reports supply threat actor attribution, TTPs mapped to MITRE ATT&CK and matching indicators, which shortens the work of describing what was observed and which known campaign it resembles. What it does not do is decide whether you hit the deadline at all, because it does not detect the incident, raises no alert, records nothing that happened on your systems and offers no submission workflow towards BACS. Detection and evidence have to come from an EDR or XDR product and from log retention; this subscription only explains a threat you are already looking at. This text is a product description and not legal advice, so have your own reporting duties assessed by qualified counsel.
No product creates NIS 2 compliance, because the directive addresses organisational measures rather than tools. NIS 2 requires essential and important entities to cover risk analysis and security policies, incident handling, business continuity and crisis management, supply chain security, security in acquisition and development, procedures to assess whether measures work, cyber hygiene and training, cryptography and access control. This service contributes to two of those categories: risk analysis, because ICS reports show which control system vulnerabilities are actually being exploited rather than merely published, and incident handling, because report indicators and YARA rules can be loaded into existing detection tooling. It contributes nothing to business continuity, supply chain security, access control, secure development or staff training, and it generates no audit evidence of its own. Buyers who need those categories covered should treat this as an addition to a protection and detection stack rather than a replacement for one.
On 20 June 2024 the US Department of Commerce, Bureau of Industry and Security, issued a Final Determination prohibiting Kaspersky from supplying anti-virus software and cybersecurity products or services in the United States or to US persons, with new sales barred from 20 July 2024 and updates ending on 29 September 2024. The same determination states that it does not apply to Kaspersky Threat Intelligence products and services, security training, or purely informational consulting and advisory services, so this reporting subscription falls outside the prohibited scope. BIS additionally placed three Kaspersky entities on its Entity List. In Germany the BSI published a warning in March 2022 recommending that users replace Kaspersky protection software, which is a recommendation rather than a sales ban, while Italy and the Netherlands restricted Kaspersky in public sector procurement. Kaspersky rejects the allegations, states that it does not engage in activity threatening national security, and has offered independent review of its code, updates and detection rules through its Transparency Initiative. The measures described are national in scope and do not restrict sale or use in Switzerland or the European Union, so in practice this affects buyers with US persons in scope, public sector contracts, or supply chain questionnaires that ask about vendor country of origin; other buyers are constrained mainly by their own procurement policy.
Partly, and only for a small number of items. It answers questions about which external threat intelligence sources you use, whether threat actors relevant to your sector are tracked, and whether detection content is updated from outside research, because the indicators, YARA rules and Suricata rules in each report are artefacts you can name in an answer. It does not answer the bulk of a typical questionnaire: endpoint protection rollout, patch status, encryption of notebooks and removable media, backup and restore testing, access control and multi-factor authentication, log retention periods, incident response times and certification status. It also produces no coverage report and no per-device record, so it cannot serve as proof that a control is actually in place anywhere in your estate. To close those gaps, a protection and detection tier from the same vendor family, such as a Kaspersky Next edition that includes EDR and central management, answers far more questionnaire items than buying a separate point product for each individual gap.
The decisive difference is threat scope, not report quality. Kaspersky sells APT Intelligence Reporting as its own subscription covering targeted attack campaigns, while this bundle adds the crimeware stream on financially motivated attacks against banks, payment processors and related infrastructure, plus the ICS stream on campaigns against industrial organisations and vulnerability analysis of widely used control systems. If you run no OT environment and no payment infrastructure, the APT stream alone carries most of the value for you. If you operate production plants, building control systems or similar equipment, the ICS stream is the specific reason to buy the bundle rather than the single subscription.
| Content | APT Intelligence Reporting | APT & Crimeware & Industrial |
|---|---|---|
| Targeted attack campaign reports | ✓ | ✓ |
| Crimeware and financial sector reports | ✕ | ✓ |
| ICS reports and control system vulnerability analysis | ✕ | ✓ |
| IoCs, YARA and Suricata rules | ✓ | ✓ |
| Access via Threat Intelligence Portal | ✓ | ✓ |
This is an intelligence subscription and not protection software: nothing is installed on a device, nothing is scanned, nothing is detected in your network and nothing is blocked. Getting value out of it requires people who can take an indicator or a YARA rule and load it somewhere, so without a SIEM, an EDR platform or an equivalent detection stack the technical half of every report stays unused. It also covers only the reporting part of the Kaspersky Threat Intelligence family, which means threat data feeds, digital footprint intelligence and cloud sandbox lookups are separate purchases and are the usual source of follow-up cost. On regional availability, the US prohibition on Kaspersky cybersecurity products expressly excludes threat intelligence services, but US-linked group policies and public sector procurement rules can still block the purchase independently of that exclusion, so check your own contractual constraints before ordering.
No. The reports are delivered through the Kaspersky Threat Intelligence Portal in a browser and are read independently of which endpoint or network products you run. The indicators and rules are vendor-neutral formats, so they can be used in third-party detection tooling.
A typical report gives an overview of the campaign, the industries and regions affected, probable attribution and objectives, and a technical analysis. Attached to that are indicators such as file hashes, domains, IPs, registry keys, service and task names and mutexes, plus YARA and Suricata rules and the TTPs mapped to MITRE ATT&CK.
Kaspersky states that more than 200 reports are released per year across the three streams. Alongside individual campaign reports there are recurring monthly activity summaries for APT and crimeware, which is what most teams use as their regular reading rhythm.