What are the key advantages of Kaspersky Crimeware Intelligence Reporting?
Portal access – Analyst service, no agent on your devices.
Crimeware focus – Ransomware, banking, ATM and PoS attacks.
Technical indicators – IoCs, YARA and Suricata rules per report.
Actor profiles – TTPs mapped to the MITRE ATT&CK framework.
Private research – Includes campaigns that are never published.
Important note – No detection, blocking or response component included.
Crimeware reports – Analysis of specific attacks on banks, ATMs and payment systems.
Researcher notes – Short updates on a specific attack, actor or new malware.
Monthly activity report – Regional overview of crimeware activity from the previous month.
Early warnings – Advance notice of new or updated malware threats.
Threat actor profiles – Aliases, malware families and full MITRE ATT&CK matrix.
Important – No agent, console, detection or blocking component is included.
Kaspersky Crimeware Intelligence Reporting is a research service covering financially motivated attacks, accessed through the Kaspersky Threat Intelligence Portal instead of being installed in your network. Kaspersky documentation also uses the name Crimeware Threat Intelligence Reporting, which is still how the service appears in older price lists and portal help pages.
Faster triage – Reports combine an executive summary with a technical appendix.
Ready detection content – YARA and Suricata rules can be loaded directly.
Attack attribution – Campaigns are linked to tracked actors and their TTPs.
Retrospective access – Earlier reports stay available while the service is active.
Non-public research – Includes campaigns that are never publicly disclosed.
Dark web reach – Researchers with access to closed criminal communities.
This service produces reading material for analysts, not alerts for administrators. It pays off where someone reads a crimeware report, extracts the indicators and turns them into detection rules in an existing SIEM or EDR. Without that capacity in-house or at a service provider, the reports remain unused.
| Requirement | Small business | Medium-sized company | Large company |
|---|---|---|---|
| Reporting obligation Switzerland | Rare | By sector | Often |
| NIS 2 in the European Union | Rare | By sector | ✓ |
| Security questionnaire from large customers | Sometimes | ✓ | ✓ |
| Own analysts to process reports and rules | ✕ | Partial | ✓ |
| This product fits | ✕ | Via provider | ✓ |
The obligation that matters here applies to operators of critical infrastructure under the revised Information Security Act, in force since 1 April 2025, and not to companies in general. Affected organisations must submit an initial report of a cyberattack to the Federal Office for Cybersecurity (BACS) within 24 hours of discovery, with a further period to complete missing details. Crimeware Intelligence Reporting supports the content of such a report: the indicators, YARA and Suricata rules and threat actor profiles help name the malware family, describe the attack path and map the observed TTPs to MITRE ATT&CK, which is exactly the information that is hardest to assemble under time pressure. What the service does not do is detect the incident, monitor your systems, retain logs, or generate and submit the report itself, so the 24-hour clock still depends entirely on your own detection and response setup. It also produces no audit evidence, because the reports describe threats in general and not events in your environment. This text is buyer guidance and not legal advice; whether your organisation is subject to the reporting obligation should be clarified with legal counsel.
No product creates compliance with the NIS 2 Directive, because the directive addresses organisational measures and management responsibility rather than software features. NIS 2 requires categories of measures including risk analysis and security policies, incident handling, business continuity and crisis management, supply chain security, vulnerability handling and disclosure, testing of effectiveness, cryptography, and access control including multi-factor authentication. Crimeware Intelligence Reporting contributes to two of these: risk analysis, by documenting which crimeware families and actors currently target your sector and region, and incident handling, by supplying the indicators and rules needed to recognise and describe a campaign. It contributes nothing to business continuity, backup, cryptography, access control, multi-factor authentication, vulnerability handling in your own systems, or the testing of measures. Buyers should also note that the reports themselves are threat research and not a management system, so they answer no governance question on their own.
Two official measures concerning the vendor are relevant and still in force. The US Department of Commerce issued a Final Determination on 20 June 2024 prohibiting Kaspersky from providing cybersecurity products and services to US persons, with the first transactions prohibited from 20 July 2024 and further prohibitions, including antivirus signature updates and the operation of the Kaspersky Security Network in the United States, from 29 September 2024. Germany's Federal Office for Information Security has warned against the use of Kaspersky antivirus software since March 2022, and confirmed in early 2026 that it maintains the warning, which is now regulated under Section 13 BSIG. In Switzerland, the Federal Office for Cybersecurity has issued neither a warning nor a sales restriction and has stated that no misuse of Kaspersky software has been reported to it; it also confirmed that there is no internal directive against the products. Kaspersky rejects the allegations as unsubstantiated, has repeatedly demanded the withdrawal of the German warning and reserves legal steps, and points to its transparency measures, including the relocation of data processing for European customers to Switzerland and the Transparency Centre in Zurich where source code can be reviewed. Independent comparative laboratory tests cover Kaspersky endpoint products rather than this reporting service, so no test result applies to it either way. In practice this affects buyers with US entities or US persons in scope, buyers bidding for public sector contracts in Germany, and buyers whose large customers exclude vendors named in national warnings; for a private Swiss company with no such exposure, the measures create no legal obstacle.
Partly, and only in one section of a typical questionnaire. It gives a documented answer to items on threat intelligence sources, on the tracking of ransomware and financially motivated actors, on the use of MITRE ATT&CK for detection engineering, and on how new indicators reach your detection stack, because you can name a subscribed commercial source with defined report types and machine-readable rules. It answers nothing on endpoint protection, patching, backup and restore testing, encryption, multi-factor authentication, log retention, access control, incident response procedures, or certifications such as ISO 27001, and it produces no evidence document that an auditor can accept, since the reports describe external threats and not your controls. A further point is worth planning for: questionnaires from larger customers increasingly ask about vendor origin and about national warnings, and this service will attract that question. The cheaper route to close the technical gaps is usually a broader bundle from the same vendor family, since Crimeware Intelligence Reporting is also sold inside the Kaspersky Threat Intelligence Bundles that add Threat Lookup, threat analysis and Digital Footprint Intelligence, rather than adding a second intelligence vendor alongside it.
The single decisive difference is threat coverage, not report quality. Bought on its own, the service covers financially motivated attacks only: ransomware, banking malware, data breaches traded on the dark web, and ATM and point-of-sale attacks. Kaspersky also sells it inside two bundles that add the other reporting tracks, and the same crimeware content is included in each. Choose the standalone service if your risk picture is criminal rather than state-sponsored; choose a bundle if you also need coverage of targeted campaigns or of industrial control systems.
| Scope | Crimeware only | APT & Crimeware | APT, Crimeware & Industrial |
|---|---|---|---|
| Crimeware reports and actor profiles | ✓ | ✓ | ✓ |
| APT reports on targeted campaigns | ✕ | ✓ | ✓ |
| ICS reports on industrial systems | ✕ | ✕ | ✓ |
| Protection or detection component | ✕ | ✕ | ✕ |
| Available to US persons | ✕ | ✕ | ✕ |
The regional limitation is the reverse of the usual pattern: because of the US prohibition on Kaspersky cybersecurity products and services, this service cannot be provided to US persons, which matters for Swiss and European groups with US subsidiaries or US staff in the security team. The second limitation is confidentiality: Kaspersky prohibits disclosure of the information contained in Crimeware Intelligence reports, and all deliverables are marked under the Traffic Light Protocol, so managed service providers cannot simply forward report content into customer deliverables. Third, the service has no delivery path into your tooling beyond manual download; automated ingestion of indicators into a SIEM is handled by separate Kaspersky products such as Threat Data Feeds and CyberTrace, which is the most common follow-up purchase. Access covers all reports and actor profiles, but the number of reports that can be downloaded depends on the bundle purchased, so check that figure against how many reports your team realistically works through. Finally, Kaspersky states that report content, technical features and format are subject to change and that not all features are available at all times.
Reports are provided as PDF, indicators of compromise in openIOC format and detection rules in YARA format, with Suricata rules where available. Executive summaries, IoCs and rules can be downloaded separately from the full report, and Master IoC and Master YARA downloads bundle all indicators and rules from all crimeware reports in one file.
No. Kaspersky prohibits disclosure of the information contained in Crimeware Intelligence reports, and every deliverable is marked according to the Traffic Light Protocol, which the customer agrees to honour. Unmarked deliverables inherit the classification of the report they belong to, so service providers should clarify handling rules before building customer-facing content on this material.
No. The reports describe campaigns, tools and infrastructure observed elsewhere and supply the indicators that identify them. Matching those indicators against your own environment requires your own logs, endpoint agents or SIEM; the monitoring of your external attack surface and data leaks is a different Kaspersky service.