<h2 style="margin-top: 0px; margin-bottom: 10px;">What is included in Kaspersky APT C&amp;C Tracking?</h2>
<p style="margin-top: 0px; margin-bottom: 0px;"><strong>APT infrastructure list</strong> – IP addresses of infrastructure connected to advanced targeted attacks.<br /> <strong>Daily updates</strong> – New findings from the Kaspersky Global Research and Analysis Team.<br /> <strong>Attribution context</strong> – APT group, operation or malware name per address.<br /> <strong>Network context</strong> – Internet service provider, autonomous system, first and last seen.<br /> <strong>Machine-readable export</strong> – CSV or JSON archive for import into security tools.<br /> <strong>Important</strong> – No agent and no management console; the service delivers data only.</p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">What are the main benefits of Kaspersky APT C&amp;C Tracking?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">Kaspersky APT C&amp;C Tracking is a subscription service inside the Kaspersky Threat Intelligence Portal that publishes IP addresses of infrastructure linked to advanced targeted attacks; there is no console and nothing to install, because the list is read in the browser or pulled through the portal API. Kaspersky now lists the service in its threat intelligence portfolio as Threat Infrastructure Tracking and has renamed the portal section accordingly, while the earlier APT C&amp;C Tracking name still appears in the product help and in the API method.<br /><br /> <strong>Blocklist input</strong> – Addresses can feed firewall, proxy and SIEM rules.<br /> <strong>Named attribution</strong> – Analysts see which APT group an address serves.<br /> <strong>Country filter</strong> – Narrows the list to the regions you monitor.<br /> <strong>No rollout</strong> – Nothing to install, no agents to maintain or update.<br /> <strong>Incident dating</strong> – First and last seen dates support attack timelines.<br /> <strong>API retrieval</strong> – The list can be pulled programmatically instead of manually.</p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Which company size is Kaspersky APT C&amp;C Tracking suitable for?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">This is analyst-facing data, not a protection product, so the deciding factor is not headcount but whether someone reads the list and acts on it. An organisation with a firewall or SIEM it can feed, and a person who reviews the matches, gets value from it. An organisation without either downloads a file it never uses.</p>
<table style="width: 100%; border-collapse: collapse; background-color: #efefef; margin-top: 15px; margin-bottom: 15px; font-size: 14px; line-height: 1.35;">
<tbody>
<tr><th style="border: 1px solid #ffffff; padding: 9px 8px; text-align: left; font-weight: bold; background-color: #dedede;">Requirement</th><th style="border: 1px solid #ffffff; padding: 9px 8px; text-align: center; font-weight: bold; background-color: #dedede;">Small business</th><th style="border: 1px solid #ffffff; padding: 9px 8px; text-align: center; font-weight: bold; background-color: #dedede;">Medium-sized company</th><th style="border: 1px solid #ffffff; padding: 9px 8px; text-align: center; font-weight: bold; background-color: #dedede;">Large company</th></tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Reporting obligation Switzerland</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Rarely</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">By sector</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Often</td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">NIS 2 in the European Union</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Rarely</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">By sector</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Often</td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Security questionnaire from large customers</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Sometimes</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Often</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Standard</td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Team able to act on IP indicators</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #d9534f; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✕</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Partial</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">This product fits</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #d9534f; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✕</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Limited</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
</tr>
</tbody>
</table>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Does Kaspersky APT C&amp;C Tracking meet the requirements of Swiss cybersecurity legislation?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">The reporting obligation under the revised Information Security Act has applied since 1 April 2025 and covers operators of critical infrastructure in Switzerland, among them energy and water suppliers, transport companies, hospitals, financial institutions and cantonal and communal authorities. Those organisations must submit an initial report to the Federal Office for Cybersecurity (BACS) within 24 hours of discovering a qualifying cyberattack, with the remaining details due within 14 days. Kaspersky APT C&amp;C Tracking supports the discovery step in a narrow way: when a monitored system contacts an address on the list, the match is a dated signal that a targeted attack may be under way, and the first and last seen fields give the reporting form a defensible timeline. It does not detect anything by itself, does not monitor your network, does not generate the report and keeps no logs on your behalf, so detection, triage and the reporting workflow all have to exist elsewhere. This overview is not legal advice; whether your organisation falls under the reporting obligation should be clarified with your own legal counsel.</p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Does Kaspersky APT C&amp;C Tracking meet the requirements of European cybersecurity legislation?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">No product makes a company compliant with the NIS 2 Directive, because the directive addresses organisational duties: risk analysis, incident handling and reporting, business continuity, supply chain security and a review of how effective the measures actually are. Kaspersky APT C&amp;C Tracking touches two of those categories. It contributes to risk analysis by naming infrastructure associated with specific threat actors, and it contributes to incident handling as an enrichment source when an analyst has to decide whether an outbound connection matters. It does nothing for business continuity, access control, encryption, staff training or supplier assessment, and it produces no audit trail of its own that an effectiveness review could rest on. Organisations in scope should treat it as one input into an existing detection process, not as one of the required measures.</p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">What should you know about official assessments of Kaspersky?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">Germany's Federal Office for Information Security (BSI) published a warning against the use of Kaspersky antivirus software on 15 March 2022. The warning is still published and still in force; since Germany's NIS 2 implementation act took effect on 6 December 2025 it is issued under section 13 of the BSI Act rather than section 7. The United States went further: on 20 June 2024 the Bureau of Industry and Security issued a Final Determination prohibiting Kaspersky from supplying antivirus software and cybersecurity products or services to US persons, cut off updates on 29 September 2024, and added AO Kaspersky Lab, OOO Kaspersky Group and Kaspersky Labs Limited to the Entity List. That determination expressly excludes Kaspersky threat intelligence, training and consulting services that are informational in nature, which is the category this service falls into. Kaspersky rejects the BSI warning as not based on an objective technical analysis and points to its transparency centres and third-party audits. Switzerland has taken neither step: the Federal Office for Cybersecurity has issued no warning and no ban, has stated that no misuse of Kaspersky software in Switzerland has been reported to it, and has confirmed that no federal directive against the products exists. The warnings concern software with deep system privileges installed on protected machines, whereas this service installs nothing; independent laboratory tests cover Kaspersky's endpoint products and do not assess this data service either way. In practice the assessments matter most for public sector tenders, defence-adjacent supply chains and customers whose own procurement rules exclude vendors of Russian origin.</p>
<p style="margin-top: 15px; margin-bottom: 15px;"><a href="#" target="_blank" data-ke-doc="norton-vs-kaspersky-2025"><strong>Norton vs. Kaspersky – Which antivirus program offers the best protection in 2025?</strong><br />A side-by-side comparison of the two vendors, useful if the official assessments have put your Kaspersky endpoint software back on the internal agenda.</a></p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Does Kaspersky APT C&amp;C Tracking help with security questionnaires from large customers?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">Yes, but only for one line of questioning. It answers the questions about external threat intelligence sources: you can name a commercial feed, state that it is updated daily, describe the attribution context each address carries, and show that indicators are imported into your firewall, proxy or SIEM. Everything else on a standard questionnaire remains open. There is no endpoint protection, no EDR, no logging or retention evidence, no patch or vulnerability management, no encryption or key management, no multi-factor authentication, no backup, no access control model and no report format built to serve as audit evidence. Two further items need a prepared answer rather than a product: the vendor's country of origin, which large customers increasingly ask about directly, and the absence of an independent certification covering this specific service. Where the remaining gaps are in intelligence coverage rather than protection, staying inside the same portal is usually the cheaper route, since Threat Data Feeds, Threat Intelligence Reporting and Digital Footprint Intelligence are licensed as separate services on the same access.</p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Which limitations should you know before buying?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">The service covers IP addresses only; domains, web addresses and file hashes are not part of it and have to come from another source. The web interface and the API are not equivalent: the interface can filter by date and by country and can export a CSV or JSON archive, while the API can list addresses and filter by country but cannot filter by date and cannot export a file, which constrains automated pipelines built on the API alone. Access is not self-service, because the portal requires credentials and a certificate issued through a Kaspersky Technical Account Manager. On regional availability, the US prohibition on Kaspersky cybersecurity products carves out threat intelligence services, so this one is not covered by it, but groups with US entities should still confirm their own procurement rules first. The most common follow-up purchase is a second intelligence service, since an IP list alone rarely answers the next question an analyst has after a match.</p>
<p style="margin-top: 15px; margin-bottom: 15px;"><a href="#" target="_blank" data-ke-doc="windows-defender-not-enough"><strong>Best antivirus? Why Windows Defender alone is not enough</strong><br />Explains what a protection layer on the endpoint actually has to do, which is the part this data service does not replace.</a></p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Frequently asked questions about Kaspersky APT C&amp;C Tracking</h3>
<h3 style="margin-top: 30px; margin-bottom: 10px;">In which formats can the IP list be exported?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">The web interface offers a download in two formats, a CSV archive or a JSON archive, both delivered as .zip files. The country filter is applied before the download, so the export contains only the regions you selected.</p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">How is access to the service granted?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">Access runs through the Kaspersky Threat Intelligence Portal with credentials issued by a Kaspersky Technical Account Manager. The second authentication factor is either an imported certificate or a one-time password from a TOTP authenticator app, where your organisation permits that method.</p>
<div class="ke-block mceNonEditable" data-ke-block="blogteaser" data-topics="sec-edr,compliance-ch-isg,compliance-nis2" data-audience="b2b" data-count="3"> </div>