What are the core benefits of Kaspersky Threat Data Feeds Mobile Threat?
No console – Data only; your own tools perform matching.
Mobile hashes – Malicious file hashes for Android and iPhone.
Botnet URLs – Mobile command and control servers with context.
Open formats – JSON, OpenIoC, CSV and STIX are supported.
SIEM connectors – Ready-made links to Splunk, QRadar and Sentinel.
Important note – No agent, no blocking, no mobile device management.
Mobile malicious hashes – File hashes with context for Android and iPhone threats.
Mobile botnet URLs – URLs and masks covering mobile botnet C&C servers.
Actionable context fields – Threat names, timestamps, geolocation and popularity per record.
Standard feed formats – Delivered as JSON, OpenIoC, CSV and STIX files.
Ready-made SIEM connectors – Splunk, QRadar, ArcSight, Azure Sentinel, MISP and more.
Important – No console, no agent, no blocking; your tools match.
Kaspersky Threat Data Feeds Mobile Threat is threat intelligence data, not protection software: it supplies mobile malware hashes and mobile botnet C&C indicators to the security tools you already operate. There is no management model of its own, because Kaspersky states that threat matching is performed by the customer's tools.
Earlier mobile detection – Records can appear before the same indicators reach OSINT.
Fewer wasted alerts – Context lets analysts prioritise instead of checking every hit.
Vendor-neutral integration – Works with your existing SIEM, firewall or gateway.
Low false positives – Filtered against allowlisting databases and validated by analysts.
Gateway deny lists – Mobile C&C URLs feed firewalls and web gateways.
Documented feed IDs – Kaspersky publishes feed IDs 67 and 139 openly.
This is an enterprise threat intelligence feed. It produces no value on its own: someone has to ingest it, match it against telemetry and act on the hits. Companies without a SIEM, threat intelligence platform or a firewall that accepts external indicator lists cannot use it at all.
| Requirement | Small business | Medium-sized company | Large company |
|---|---|---|---|
| Reporting obligation Switzerland | By sector | By sector | By sector |
| NIS 2 in the European Union | Rarely | ✓ | ✓ |
| Security questionnaire from large customers | Sometimes | ✓ | ✓ |
| SIEM, TIP or firewall that ingests feeds | ✕ | Sometimes | ✓ |
| This product fits | ✕ | Rarely | ✓ |
In Switzerland the revised Information Security Act obliges operators of critical infrastructure to report cyberattacks to the Federal Office for Cybersecurity (BACS) within 24 hours of discovery, so the duty follows the sector rather than the headcount. The feed supports that duty in one narrow way: when a mobile hash or a mobile botnet C&C URL from your logs matches a record, you receive the threat name and first-seen timestamp, which shortens the classification step of the report. It does not detect the incident for you, because it contains no scanning engine, no agent and no telemetry collection of its own. It also produces no case file, no timeline and no report template, so the 24-hour window still depends on your logging, your alerting and a named person who is on call. Nothing in the product ensures that a report is filed on time, and no software product makes a company compliant. This description is a product overview and not legal advice; whether your organisation falls under the reporting obligation should be clarified with qualified counsel.
No product creates NIS 2 compliance, because the directive addresses organisational risk management, not the purchase of a specific tool. NIS 2 requires measures in categories such as risk analysis and security policies, incident handling, business continuity, supply chain security, cyber hygiene, access control and the use of multi-factor authentication. This feed contributes to incident handling and to threat intelligence sharing: mobile indicators arrive continuously and can be correlated with events your monitoring already collects. It contributes nothing to access control, multi-factor authentication, encryption, backup, vulnerability handling or staff training, and it holds no evidence of its own that an auditor could inspect. Buyers who need coverage of those categories have to source them separately.
Two official measures are relevant and both are still in force. Germany's Federal Office for Information Security published a warning on 15 March 2022 against the use of Kaspersky anti-virus software under the German BSI Act; it has not been withdrawn and was carried over into the amended act that took effect on 6 December 2025. On 20 June 2024 the US Department of Commerce issued a Final Determination prohibiting Kaspersky anti-virus and cybersecurity products for US persons, with new agreements barred from 20 July 2024 and signature and codebase updates from 29 September 2024. The determination states explicitly that it does not apply to Kaspersky Threat Intelligence products and services, which is the category this feed belongs to. Kaspersky's own position is that the German warning was not based on an objective technical analysis and that the US decision reflected the geopolitical climate rather than an evaluation of its products. In practice this matters most for public sector contracts and for suppliers whose customers impose vendor-origin clauses; because the feed is text data matched by your own tools rather than software with system privileges, some organisations treat it differently from an installed agent, but the contractual wording your customer uses decides that, not the technical distinction.
Partly, and only in one section of a typical questionnaire. It answers items on external threat intelligence sourcing, on whether mobile-specific indicators are covered for Android and iPhone, on the formats you can ingest, and on which detection platforms the data reaches. It does not answer the questions that carry the most weight: whether endpoint and mobile protection is deployed, whether devices are enrolled in a mobile device management platform, how patching is handled, whether disks are encrypted, whether multi-factor authentication is enforced, how long logs are retained, or how incidents are triaged and escalated. Those gaps cannot be closed by adding more feeds. The cheaper route is usually to extend within the same family first, since broader Kaspersky feed packages add desktop hashes, malicious and phishing URLs and IP reputation, and Kaspersky CyberTrace supplies the matching layer that the feed itself lacks, before mixing a second vendor into the same workflow. Endpoint, mobile management and identity controls remain separate purchases in every case.
The decisive difference is desktop coverage: Mobile Threat carries only the two mobile feeds, while the larger package adds the desktop hash and URL feeds. In Kaspersky's own documentation the two feeds sold here are named Mobile Malicious Hash Data Feed (ID 67) and Mobile Botnet Data Feed (ID 139), and buyers searching for those names will find the same content. Kaspersky publishes more than 25 out-of-the-box feeds in total, so the retail packages are subsets of one catalogue rather than different product generations. Choose Mobile Threat only if your desktop indicators already come from another source, otherwise the mobile-only scope leaves a visible hole in the same SIEM.
| Feed content | Mobile Threat | URL & Hash & Mobile Threat |
|---|---|---|
| Mobile malicious hashes (Android, iPhone) | ✓ | ✓ |
| Mobile botnet C&C URLs | ✓ | ✓ |
| Desktop malicious hashes | ✕ | ✓ |
| Malicious and phishing URL feeds | ✕ | ✓ |
| IP reputation and allowlisting feeds | ✕ | ✕ |
| Matching engine included | ✕ | ✕ |
The feed protects nothing by itself. Kaspersky states that matching must be performed by the customer's tools because only text-based data is delivered, so a hit only exists where your SIEM, gateway or threat intelligence platform already produces the file hashes and URLs to compare against. Mobile devices are not scanned and are not enrolled, which means a phone outside the corporate network generates no events to match in the first place. No region-restricted features were found for the feeds themselves, but the vendor's regulatory situation described above is the availability question that matters for public sector and supply-chain-bound buyers in Switzerland and the European Union. The most common follow-up purchases are a matching layer such as Kaspersky CyberTrace, additional feeds for desktop indicators, and analyst time, since raw indicators without someone to triage them simply add rows to a database.
No. The feed can be loaded directly into a SIEM, next generation firewall, web gateway or threat intelligence platform, and Kaspersky provides connectors for Splunk Enterprise Security, IBM QRadar, ArcSight ESM, RSA NetWitness, Azure Sentinel, MISP, ThreatConnect, EclecticIQ, ThreatQ, Anomali ThreatStream, Maltego, Cisco Firepower and Suricata, plus a REST API. CyberTrace is a separate Kaspersky product that performs the matching before events reach the SIEM, which reduces SIEM load but is not required.
Kaspersky aggregates it from the Kaspersky Security Network, its own web crawlers, a botnet monitoring service running 24/7/365, spam traps, its research teams and partners. The raw data is then filtered using statistical criteria, sandboxes and heuristic engines, analyst validation and allowlisting checks before it reaches the feed.
Nothing automatic. The matching tool raises the alert and applies whatever rule you configured, and the feed supplies the context that accompanies it, such as the threat name, the timestamp, geolocation and popularity of the object. Whether the connection is blocked, the device is isolated or a ticket is opened is decided entirely by your own tooling and process.