What are the key advantages of Kaspersky Threat Infrastructure Tracking?
Portal service – No agent or console; browser and API access.
Threat IPs – Daily updated list of attacker infrastructure addresses.
Actor context – Names the threat group or malware per address.
Country filter – Narrow the list to one country.
API export – Machine-readable export into existing security tools.
Important note – Supplies intelligence data only, provides no protection.
Download: Kaspersky Threat Infrastructure Tracking
Threat infrastructure IP list – IP addresses linked to advanced threats, updated daily.
Actor and malware context – The threat group, operation or malware behind each address.
Supporting IP context – Provider, autonomous system, plus first and last seen dates.
Country and date filters – Narrow results to one country or an observation window.
Machine-readable export – Push address lists into existing security tools via API.
Important – No agent, console or blocking function; this delivers data only.
Kaspersky Threat Infrastructure Tracking is a subscription service in the Kaspersky Threat Intelligence family that reveals the IP addresses of infrastructure used in advanced attacks. There is no agent and no device console: analysts work in the Kaspersky Threat Intelligence Portal or pull the same data through its RESTful API.
Country-level view – Filter active threat infrastructure down to a single country.
Faster attribution – Link an observed address to a known threat group.
Daily research updates – Fed by findings from Kaspersky Global Research and Analysis Team.
Automation ready – RESTful API and export feed your existing detection tooling.
Pivot points – Associated hosting addresses support wider infrastructure hunting.
Response support – Speeds incident response and threat hunting work across regions.
The deciding factor is not headcount but whether someone in the organisation can act on a list of hostile IP addresses. Kaspersky positions the service for CERTs, national SOCs and national security agencies, which is a direct signal about the level of in-house analysis it expects.
| Requirement | Small business | Medium-sized company | Large company |
|---|---|---|---|
| Reporting obligation Switzerland | Rarely | By sector | Often |
| NIS 2 in the European Union | Rarely | By sector | Often |
| Security questionnaire from large customers | ✓ | ✓ | ✓ |
| Analyst able to act on IP data | ✕ | Partial | ✓ |
| This product fits | ✕ | Partial | ✓ |
The Swiss reporting obligation applies to operators of critical infrastructure, not to every company. Since 1 April 2025 the revised Information Security Act requires those operators to report a cyberattack to the Federal Office for Cybersecurity (BACS) within 24 hours of discovering it, with a further 14 days to complete the report. Threat Infrastructure Tracking supports the work that happens before that clock starts: it lets an analyst decide quickly whether an address seen in firewall or proxy logs belongs to known attacker infrastructure and which threat group it has been associated with, which is exactly the kind of detail a report has to contain. It does not detect the incident for you, does not write or submit the report, and covers none of the organisational duties around incident handling and escalation. Whether your organisation falls under the obligation is a legal question, and this text is not legal advice.
No product makes an organisation NIS 2 compliant, because the directive addresses management responsibility and processes rather than software features. NIS 2 requires essential and important entities to maintain risk analysis and information security policies, incident handling, business continuity, supply chain security, and procedures to assess whether the measures actually work. Threat Infrastructure Tracking contributes to incident handling and to risk analysis: it supplies external context on attacker infrastructure that internal logs alone cannot provide, and the country filter narrows that context to the regions an organisation operates in. It contributes nothing to business continuity planning, supply chain assessment, access control, staff training, or the governance duties that sit with management. Treat it as one input into a detection and response process that has to exist independently of it.
Switzerland has issued no warning and no ban. The Federal Office for Cybersecurity (BACS) has stated that it warns only where it holds confirmed technical indications of a risk, that no misuse of Kaspersky software has been reported to it in Switzerland, and that no federal directive prohibits the products. In the European Union, the German federal information security authority has warned against the use of Kaspersky virus protection software since 15 March 2022; that warning is still published and was re-based on amended German law in December 2025. It is explicitly limited to the virus protection portfolio, and the authority states that it has made no assessment of other Kaspersky products. In the United States, the Department of Commerce issued a Final Determination in June 2024 prohibiting Kaspersky from supplying anti-virus and cybersecurity products to US persons, with new business ending on 20 July 2024 and updates ending on 29 September 2024; that determination expressly does not apply to Kaspersky Threat Intelligence products and services that are purely informational or educational, which is the category this service falls into. Kaspersky rejects the assessments, has asked the German authority to withdraw its warning, and points to its Global Transparency Initiative, under which threat-related data from European users is processed in data centres in Zurich and source code can be reviewed at a transparency centre there. Independent recognition of the intelligence business continues in parallel: Frost and Sullivan named Kaspersky a Leader in its Frost Radar for Cyber Threat Intelligence in 2024. In practice this matters most if you bid for public sector contracts, work with German authorities, or answer supply chain questionnaires that ask about vendors subject to state warnings; for a private Swiss or EU company without those requirements it is a risk decision, not a legal obstacle.
Partly, and only in one section. Questionnaires usually ask whether you use an external threat intelligence source, whether you can identify known malicious infrastructure, and whether that intelligence actually reaches your detection tooling. This subscription lets you answer those three with a named source, a daily update cadence, and a documented API integration path instead of a general statement. It answers nothing about endpoint protection coverage, patch levels, device encryption, backup and recovery testing, access control, staff training, or incident response arrangements, which is where the bulk of a questionnaire sits. It also produces no audit evidence: there is no report showing that an alert was seen, triaged and closed. If those gaps matter, close them inside the same family first, since Kaspersky Next EDR and XDR tiers cover endpoint detection and reporting and Kaspersky Threat Intelligence Reporting covers the analyst-written intelligence questions, which is usually cheaper than adding a second vendor and a second console.
The decisive difference is what the data is for. Threat Infrastructure Tracking answers an investigative question, namely which attacker infrastructure is active and who is behind it, and it can be narrowed to a single country. Threat Data Feeds answer a detection question, feeding indicators into security controls so that they block or alert automatically. Both are separate subscriptions in the Kaspersky Threat Intelligence family, and buying one does not include the other.
| Aspect | Threat Infrastructure Tracking | Threat Data Feeds |
|---|---|---|
| Main purpose | Track attacker infrastructure | Enhance existing detection |
| Data scope | Threat infrastructure IP addresses | 30+ feeds, IT and OT |
| Delivery | Portal and RESTful API | Feed into security controls |
| Typical user | CERT, SOC, national agency | Teams running security controls |
This is an intelligence data source, not a security control: there is no agent, no policy console and no ability to block anything on its own. Its scope is IP addresses of threat infrastructure, so file hashes, domains and URL reputation are handled by other services in the same family such as Threat Lookup and Threat Data Feeds, and buyers expecting one all-indicator subscription usually end up purchasing twice. Kaspersky positions the service for CERTs, national SOCs and national security agencies, which is worth taking literally: without an analyst who can act on an IP list, the subscription produces no measurable effect. On regional availability we found no restriction for Swiss or European buyers; the one region-specific finding is the United States, where the June 2024 Commerce Department determination covers Kaspersky anti-virus and cybersecurity products but expressly excludes purely informational threat intelligence services. Access runs entirely through the Kaspersky Threat Intelligence Portal, so the data arrives over the internet by browser or API rather than from a component you host yourself.
Yes. The list can be exported in a machine-readable format, and viewing, filtering by date and country, and exporting are all available through the RESTful API as well as the web interface. A scheduled job can therefore pull the current set into a SIEM or firewall without anyone copying addresses by hand.
No. Analyst-written reporting on APT, crimeware and ICS threats is Kaspersky Threat Intelligence Reporting, and monitoring of leaked data and underground discussion about your own organisation is Kaspersky Digital Footprint Intelligence. Threat Infrastructure Tracking delivers the infrastructure IP data set only.