What are the core benefits of Kaspersky Threat Data Feeds Ransomware URL?
Standalone feed – No console or agent, runs in existing tools.
Ransomware URLs – URLs, domains and hosts serving ransomware.
Fast refresh – JSON feed updated every twenty minutes.
SIEM integration – Direct ingest or via Kaspersky CyberTrace.
Format conversion – Converts to STIX, OpenIoC, CSV and text.
Important note – Blocks nothing itself, your controls do that.
Ransomware URL indicators – URLs, domains and hosts where ransomware is hosted.
Threat context data – Threat name, timestamp, popularity and resolved IP address.
JSON feed delivery – Native JSON, refreshed every twenty minutes over HTTPS.
Format conversion utility – Feed Utility converts to STIX, OpenIoC, CSV, text.
TAXII collection access – STIX objects retrievable from the Kaspersky TAXII server.
Important – No console, no agent and no blocking engine included.
Kaspersky Threat Data Feeds Ransomware URL is a machine-readable indicator feed covering web resources that host or serve ransomware, sold as a standalone data subscription. There is no management console and no agent: the feed is consumed by systems you already run, such as a SIEM, a next-generation firewall, a web gateway or Kaspersky CyberTrace, and Kaspersky documentation also refers to the family as Kaspersky Threat Intelligence Data Feeds.
Firewall blocklist source – Feeds NGFW external connectors as a dynamic block list.
SIEM alert enrichment – Matches proxy and DNS logs against known ransomware infrastructure.
CyberTrace offload – Matching runs outside the SIEM, cutting correlated event volume.
Narrow ransomware scope – A shorter list than a general malicious URL feed.
Twenty-minute refresh – Newly seen hosting URLs reach your controls the same hour.
Vendor-neutral integration – Works with third-party SIEM, proxy and gateway products.
This is a feed, not a product with a user interface. It only pays off if a system already exists that can ingest indicators and someone reviews what the match produces. Companies without their own SIEM, firewall management or security service provider get no usable output from it.
| Requirement | Small business | Medium-sized company | Large company |
|---|---|---|---|
| Reporting obligation Switzerland | Rarely | By sector | Often |
| NIS 2 in the European Union | Rarely | By sector | Usually |
| Security questionnaire from large customers | Occasionally | Often | Standard |
| Own SIEM, firewall or TI platform to ingest indicators | ✕ | Partial | ✓ |
| This product fits | ✕ | Limited | ✓ |
The duty under the revised Information Security Act falls on operators of critical infrastructure, not on every Swiss company, though smaller suppliers are frequently pulled in through customer contracts. Affected operators must report a cyberattack to the Federal Office for Cybersecurity (BACS) within 24 hours of discovery, which means the discovery has to happen first and has to be documented. This feed supports exactly that one point: a match between a proxy, DNS or firewall log entry and a known ransomware hosting URL produces a dated, attributable detection event that can be cited in the report. It does not detect anything by itself, because the matching engine, the log retention and the person reviewing the alert all have to be in place already. It covers no other part of the obligation: no incident classification, no forensic timeline, no notification workflow to BACS and no evidence archive. This text is not legal advice, and your own reporting duties should be assessed with qualified counsel.
No product creates NIS 2 compliance, because the directive addresses organisational duties rather than software features. The measure categories it requires include risk analysis, incident handling, business continuity and backup management, supply chain security, and accountability of management bodies. This feed touches two of them: for incident handling it supplies external indicators that turn an unremarkable outbound connection into a named detection, and for supply chain security it is a documented commercial data source you can name when a customer asks how your detection content is kept current. It does nothing for business continuity, backup and restore, crisis management, or the governance and training duties the directive places on management. It also produces no report on its own, so the notification deadlines under NIS 2 are met by your processes and not by the feed.
Two official actions are on record and both are still in force. Germany's Federal Office for Information Security (BSI) issued a public warning against antivirus software from the manufacturer Kaspersky in March 2022; it remains in place in 2026, is now regulated under Section 13 of the BSI Act following the German NIS 2 implementation of December 2025, and BSI has confirmed publicly that it continues to maintain it. In June 2024 the US Department of Commerce, through its Bureau of Industry and Security, issued a Final Determination prohibiting Kaspersky from providing cybersecurity and antivirus products or services to US persons, with resale, integration and licensing for resale prohibited from 29 September 2024. Kaspersky rejects both positions, describing the US decision as driven by the geopolitical climate and theoretical concerns rather than by an evaluation of its products, and has formally pressed BSI to withdraw the warning. Neither decision rests on a published technical finding of malicious code in Kaspersky software, and independent laboratory testing of Kaspersky products has continued outside the United States. In practice this matters where procurement rules bite: German public-sector contracts, organisations whose customers apply BSI recommendations down their supply chain, any entity that qualifies as a US person, and tenders that ask about vendor country of origin. Buyers outside those categories face no sales restriction in Switzerland or the European Union, and the assessment is yours to make.
Partly, and mainly in one row. Questionnaires typically ask whether you use external threat intelligence, how current that intelligence is, and how it reaches your detection systems; a licensed commercial feed with a documented twenty-minute refresh cycle and a named integration path into SIEM or firewall answers those three items with a verifiable fact instead of an assertion. It answers nothing else. Endpoint protection coverage, patch status, multi-factor authentication, disk encryption, backup and restore testing, log retention periods, incident response plans, staff awareness training, access reviews and subprocessor lists all remain open, and the feed produces no report or dashboard of its own, so any evidence has to be exported from your SIEM or firewall rather than from Kaspersky. If several rows are open at once, adding further feeds from the same Kaspersky family, or moving up to the Kaspersky Threat Intelligence Portal for reporting and lookups, is usually cheaper to operate than sourcing a second intelligence vendor, because the delivery formats and the Feed Utility stay the same. Where the gap is operational rather than informational, such as backup testing or response planning, no feed will close it and the work has to be scheduled.
The decisive difference is scope, not data quality. The Ransomware URL feed covers only web resources connected to ransomware, while the Malicious URL feed covers malicious web resources of all kinds and is therefore the far larger list. That makes the ransomware feed the better choice when you want a short, high-signal blocklist for a firewall or gateway, and the malicious URL feed the better choice when you want broad coverage in a SIEM that can absorb the volume. Both are delivered natively in JSON and both use URL masks, so a control that cannot process masks needs Kaspersky CyberTrace as the matching engine. Within the family, an exact-URL variant is documented for the malicious URL feed but not for the ransomware feed.
| Property | Ransomware URL Data Feed | Malicious URL Data Feed |
|---|---|---|
| Indicator scope | Ransomware web resources | All malicious web resources |
| Relative list size | Narrower | Broader |
| Native format | JSON | JSON |
| Documented update interval | 20 minutes | 20 minutes |
| Exact-URL variant in the family | Not documented | ✓ |
| Availability to US persons | Prohibited | Prohibited |
The clearest regional limitation is the US Final Determination: Kaspersky cybersecurity products and services, including resale and integration into other services, may not be provided to US persons, which rules the feed out for US subsidiaries and for service providers with US-based clients. The second is architectural: the feed contains no console, no agent and no blocking engine, so a SIEM, next-generation firewall, secure gateway or Kaspersky CyberTrace has to be in place and correctly configured before a single match is produced. The third is coverage: this feed lists web resources where ransomware is hosted, which means ransomware arriving through a mail attachment, exposed RDP, stolen credentials or lateral movement generates no match here, and file hashes belong to the separate hash feeds. Kaspersky also publishes META-labelled regional feed variants whose coverage is tuned to that region while the standard feeds target worldwide coverage, so the variant you subscribe to should follow where your traffic actually goes. Finally, the feed uses URL masks, and controls that cannot process masks either need the matching engine in CyberTrace or a converted output produced with the Kaspersky Feed Utility.
No. This feed contains URLs, domains and hosts with context. File hashes are delivered by the separate hash feeds in the same family, such as the Malicious Hash Data Feed, which is a separate subscription.
Kaspersky publishes demo feeds for evaluation and integration testing, and documents that they have lower detection rates than the production feeds. They are suitable for confirming that your SIEM or firewall parses the format correctly, not for judging coverage.
No. The feed is designed for direct integration into third-party security controls such as SIEM systems, next-generation firewalls and secure mail or web gateways, including through STIX over TAXII. Kaspersky CyberTrace is optional and is used to move indicator matching off the SIEM.