How we combat cybercrime
GRI 3-3
We cultivate international cooperation to combat digital offenses
Key documents
-
Kaspersky's internal policy governing how law enforcement requests are to be handled (approved in September 2021 by the Company's top managers) -
Agreement with INTERPOL on jointly combating cybercrime under the Gateway project -
Agreement with AFRIPOL on cooperation in preventing and combating cybercrime -
Memorandums of cooperation with various cybersecurity agencies and law enforcement agencies
We conduct joint operations with INTERPOL and AFRIPOL
-
exchange of expert information on the latest types of malware and cyberattack methods -
participating in joint operations around the world to identify and combat cybercrime -
cybersecurity training and consulting for INTERPOL and other law enforcement agencies
Results of joint operations
Operation Synergia
September – November 2023
-
More than 50 INTERPOL member states helped identify and block infrastructure used for phishing, malware distribution, and ransomware attacks. -
31 people were detained. -
26 arrests in Europe, where most of the servers were taken down. -
Hong Kong police took down 153 servers, Singapore police — 86 servers. -
Authorities in South Sudan and Zimbabwe took down the largest number of servers on the African continent and arrested four people .
Operation against Grandoreiro
March 2024
Operation Synergia II
April – August 2024
-
More than 100 suspects were identified, 41 of whom were arrested. -
Around 30,000 suspicious IP address es and servers were detected (more than 75 % were blocked). -
59 servers and 43 electronic devices were seized.
Operation Serengeti
September – October 2024
-
More than 1,000 suspects were detained. -
134,089 malicious infrastructure objects were neutralized
Operation Red Card
March 2025
-
There were 306 arrests in the region. -
Approximately 2,000 devices were seized.
Operation Secure
January – April 2025
-
Law enforcement agencies from 26 participating countries and INTERPOL private sector partners joined the operation. -
More than 30 suspects were detained (including 18 in Vietnam). -
More than 20,000 illegitimate IP address es and domains were blocked. -
More than 40 servers were seized. -
More than 216,000 victims were warned to take immediate protective measures.
Operation Serengeti 2.0
June – August 2025
-
More than 1,200 suspects were detained. -
11,432 malicious infrastructure objects were neutralized. -
$97.4 million in damages were recovered.
We expand our partner ecosystem
-
2024 Summer Olympics in Paris — Our experts helped detect phishing attacks and other fraudulent activity. We provided cyberthreat intelligence to INTERPOL as part of Project Stadia , INTERPOL's initiative to protect major international events. -
Singapore Grand Prix, as part of the 2025 Formula One World Championship — We provided cyberthreat intelligence to protect participants from digital risks.
-
No More Ransom (jointly with Europol) — Over nine years of work, this alliance has helped more than 6 million users recover their data without paying ransom -
Coalition Against Stalkerware -
Geneva Dialogue -
Paris Call for Trust and Security in Cyberspace -
Council of Europe -
World Internet Conference (member of the High Level Advisory Council) -
International Telecommunication Union -
International Organization for Standardization (ISO) -
Smart Africa Alliance and many other organizations
We research targeted attacks and advanced threats
Key trends in cyberthreat landscape
Phishing and spam campaign s
Threats in the financial sector and sophisticated attacks
In 2025, the financial sector faced multilayered threats: attacks on users’ smartphones with banking Trojans as well as NFC-relay attacks, attacks through instant messaging apps and telephone fraud and supply chain attacks.
Increased financially‑motivated crime
Automated attacks and the use of AI
Threats to mobile devices
Supply chain attacks
We help develop legislation
We help develop standards
We share our expertise
-
UN Open‑Ended Working Group on Information and Communication Technologies (within an informal dialogue under the auspices of the Chair of the OEWG) -
consultations of the UN Ad Hoc Committee to Elaborate a Comprehensive International Convention on Countering the Use of Information and Communications Technologies for Criminal Purposes. -
UN Internet Governance Forum, UN Global Digital Compact -
African Cyber Defense Forum. -
Geneva Dialogue working groups -
INTERPOL expert working groups -
World Internet Conference (China) -
Cyber Security Summit (China) -
it‑sa Expo&Congress (Germany) -
Singapore International Cyber Week (Singapore)
Results of work combating threat actors
-
GReAT has uncovered evidence linking the HackingTeam successor, Memento Labs, to a new wave of cyberespionage attacks using Dante spyware. The discovery stems from an investigation into Operation ForumTroll, an Advanced Persistent Threat (APT) campaign that exploited a zero‑day vulnerability in Google Chrome. The research was presented at the Security Analyst Summit 2025, taking place in Thailand. -
Kaspersky Threat Research expertise center has discovered a new data‑stealing Trojan, SparkCat, active in AppStore and Google Play since at least March 2024. This is the first known instance of optical recognition‑based malware appearing in AppStore. SparkCat uses machine learning to scan image galleries and steal screenshots containing cryptocurrency wallet recovery phrases. -
Kaspersky’s Global Research and Analysis Team (GReAT) have uncovered an ongoing cyberespionage PassiveNeuron campaign, that targets Windows Server systems in government, financial and industrial organizations across Asia, Africa and Latin America. The activity has been observed since December 2024 and continued through August 2025. -
Kaspersky’s Global Emergency Response Team has identified a previously unseen ransomware strain in active use, deployed in an attack following the theft of employee credentials. The ransomware, dubbed “Ymir,” employs advanced stealth and encryption methods. It also selectively targets files and attempts to evade detection.
Our plans for 2026
-
Help shape the legal framework for combating cybercrime. -
Train and upskill experts, conduct training sessions on relevant cybersecurity topics. -
Collaborate with external organizations and establish partnerships with government institutions to share information on cyberthreats. -
Regularly update software and technology for reliable protection against cyberthreats.