What are the key advantages of Kaspersky Threat Data Feeds - Crimeware IOC?
No console – Data feed consumed by your existing SIEM.
Crimeware focus – Indicators from financially motivated cybercrime campaigns only.
Three feeds – Hashes, malicious domains and YARA hunting rules.
Fast updates – New indicators published on a three-hour cycle.
Open formats – JSON converts to STIX, OpenIOC, CSV, Snort.
Important note – No endpoint protection and no IP indicators.
Crimeware Hash Data Feed – Hashes from Kaspersky Crimeware Reports with investigation context.
Crimeware URL Data Feed – Domains behind the fraud infrastructure described in Crimeware Reports.
Crimeware YARA Data Feed – Rules for hunting crimeware artefacts across local networks.
Three-hour update cycle – New records follow each Crimeware Reports publication.
HTTPS and TAXII delivery – Client certificate download or token-based TAXII access.
Important – No IP indicators; the IP feed is licensed separately.
Kaspersky Threat Data Feeds - Crimeware IOC is a subscription to three machine-readable indicator feeds covering financially motivated cybercrime campaigns. It has no console and no agent of its own: the data is consumed by the SIEM, threat intelligence platform or network security controls you already operate.
Report-linked indicators – Every entry traces back to a published Crimeware Report.
Vendor-neutral formats – JSON output converts to STIX, OpenIOC, CSV or Snort.
Existing SIEM integration – Connectors exist for Splunk, QRadar, ArcSight, Sentinel and MISP.
Retrospective hunting – YARA rules search stored files after an alert lands.
Alert prioritisation – Context fields let analysts rank matches before escalation.
Firewall enrichment – High-confidence deny lists enrich next-generation firewall policies.
This is a data product, not a protection product. It only pays off where someone already runs a system that can match indicators against live events and where an analyst reads the results. A company without a SIEM, a threat intelligence platform or an IOC-capable firewall has nothing to feed the data into.
| Requirement | Small business | Medium-sized company | Large company |
|---|---|---|---|
| Reporting obligation Switzerland | Rarely | By sector | By sector |
| NIS 2 in the European Union | ✕ | By sector | By sector |
| Security questionnaire from large customers | ✓ | ✓ | ✓ |
| SIEM or TIP able to ingest IOC feeds | ✕ | Sometimes | ✓ |
| This product fits | ✕ | Limited | ✓ |
The obligation applies to operators of critical infrastructure named in the revised Information Security Act, including energy and drinking water supply, transport undertakings, listed hospitals, cloud and data centre providers, and cantonal and communal administrations. Since 1 April 2025 these organisations must report a cyberattack to the Federal Office for Cybersecurity (BACS) within 24 hours of discovery, with a further 14 days to complete an incomplete first report. This feed supports the content of that report in one specific way: a hash or domain match that resolves to a named Kaspersky Crimeware Report gives the reporting team an attribution and a campaign description within the first hours, instead of an unidentified binary. It does not detect the attack, does not produce telemetry, does not keep a log history, and offers no reporting workflow, so the detection, the timeline and the report itself still come from your endpoint protection, EDR and SIEM. Whether your organisation is subject to the reporting obligation at all depends on its sector and function, and this text is not legal advice.
No product creates NIS 2 compliance, because the directive addresses organisational measures and management accountability rather than software features. NIS 2 requires entities in scope to maintain risk analysis policies, incident handling, business continuity and crisis management, supply chain security, security in acquisition and development, procedures to assess the effectiveness of measures, cyber hygiene and training, cryptography, access control and multi-factor authentication. This feed contributes to two of those categories: incident handling, by shortening the identification step through indicator context, and supply chain security, by covering the fraud infrastructure used against suppliers and their customers. It contributes nothing to business continuity, access control, multi-factor authentication, cryptography, training, or vulnerability handling and disclosure. It also produces no evidence of the measure-effectiveness assessment the directive expects, which remains a documentation task for your own organisation.
Two official measures concerning the vendor are in force. Germany's Federal Office for Information Security issued a warning on 15 March 2022 recommending that applications from Kaspersky's anti-virus software portfolio be replaced with alternative products; the office stated that it made no assessment of other Kaspersky products. That warning remains published and, since the amended act took effect on 6 December 2025, is regulated under Section 13 BSIG. Separately, the US Department of Commerce Bureau of Industry and Security issued a Final Determination on 20 June 2024 prohibiting Kaspersky from entering new agreements with US persons from 20 July 2024 and from supplying signature and codebase updates or operating the Kaspersky Security Network in the United States from 29 September 2024; three Kaspersky entities were added to the Entity List. Kaspersky rejects the German warning as unjustified and has continued to pursue legal action against it, and stated at the time of the US determination that the decision does not affect its ability to sell threat intelligence offerings and training in the United States. Neither measure rests on a finding that Kaspersky research data is technically inaccurate; both concern vendor jurisdiction and trust. In practice this matters most to public sector contracts, to suppliers of German federal bodies, and to organisations whose customers apply origin-of-vendor criteria in procurement, and it is the buyer's decision.
Partly, and only in the threat intelligence block. It answers questions on whether commercial threat intelligence is subscribed to, which indicator types are ingested, how often detection content is refreshed, and whether indicators carry provenance that an analyst can trace to a source report. It answers nothing in the far larger remainder of a typical questionnaire: no endpoint protection coverage, no patch management, no encryption, no multi-factor authentication, no backup and recovery, no access control, no log retention period, no documented incident response process, no certification of the buyer's own management system, and no sub-processor list. It can also raise a question rather than close one, because origin-of-vendor items increasingly appear in supplier questionnaires and this feed introduces a Russian-headquartered vendor into the answer. The cheaper route to closing the technical gaps is usually a higher edition within the Kaspersky Next family, which covers endpoint, EDR and management reporting under one vendor answer, rather than combining feeds from one vendor with protection from another and having to explain both.
The decisive difference is the attacker being tracked, not the data quality. Crimeware IOC covers financially motivated campaigns described in Kaspersky Crimeware Reports, which is what most commercial companies actually encounter. APT IOC covers targeted campaigns run by advanced persistent threat actors and is relevant where an organisation has reason to expect state-aligned interest. The second practical difference is coverage of network indicators: the APT package includes an IP feed, the Crimeware package does not.
| Property | Crimeware IOC | APT IOC |
|---|---|---|
| Threat focus | Fraud campaigns | Targeted campaigns |
| File hash indicators | ✓ | ✓ |
| Domain and URL indicators | ✓ | ✓ |
| IP address indicators | ✕ | ✓ |
| YARA rules | ✓ | ✓ |
| Source of the indicators | Crimeware Reports | APT Reports |
On regional availability, the US prohibition described above is the relevant restriction: Kaspersky may not enter new agreements with US persons, and although the vendor states that threat intelligence is unaffected, a buyer with US entities or US-based staff should clarify this before purchase. The package contains hashes, domains and YARA rules only; the Crimeware IP Data Feed exists in the Kaspersky catalogue but is licensed separately, which is the most common follow-up purchase. Because new records appear when a Crimeware Report is published rather than continuously, this is a curated campaign feed and not a high-volume commodity blocklist, a role filled by the separate Malicious URL and Malicious Hash feeds. Consuming the YARA rules requires a scanning engine that can execute them, which not every SIEM provides. Finally, the feed protects nothing on its own: without endpoint protection or EDR underneath it, a match tells you an incident happened but cannot stop it.
No. It contains data, not a protection engine, and it installs no agent on any device. It is bought in addition to endpoint protection, not instead of it.
Yes. The feed is delivered over HTTPS with a Kaspersky client certificate, and the most requested feeds are also available over TAXII with token-based authentication, so any system that can ingest those formats will work. Kaspersky CyberTrace is a separate product that performs the matching before events reach the SIEM, which reduces SIEM load, but it is not required.
The Malicious Hash and Malicious URL feeds cover prevalent and emerging malware broadly and are built for volume blocking. Crimeware IOC is narrower and analyst-oriented: each indicator belongs to a documented fraud campaign, which is what makes attribution possible during an investigation.