Vendor lineage
Kaspersky
World-class malware research and a geopolitical problem, in the same company, both real.
Kaspersky Lab was founded in Moscow in 1997 by four people: Eugene Kaspersky, Natalya Kaspersky, Alexey De-Monderik and Vadim Bogdanov, who left a company called KAMI to keep developing the antivirus engine they had been building since 1991. It was called AVP, for AntiViral Toolkit Pro, and was renamed Kaspersky Anti-Virus after an American firm registered the AVP trademark in the United States.
Eugene Kaspersky's route into the field is unusual and it is the fact most often cited about him. At sixteen he entered the Technical Faculty of the KGB Higher School, graduating in 1987 with a degree in mathematical engineering, and served as a software engineer in Soviet military intelligence. His interest in security began prosaically: in 1989 his work computer caught the Cascade virus and he wrote a program to remove it.
**Natalya Kaspersky built the business, and that is usually left out.** She took over distribution of the toolkit in September 1994, when it was earning one or two hundred dollars a month. Within a year it was making $130,000, in 1996 over $600,000, and in 1997 more than a million - which is what made founding an independent company possible. She launched the company foundation in June 1997, was central to choosing the name, and served as chief executive for more than ten years. The initial split was Eugene 50%, De-Monderik and Bogdanov 20% each, and Natalya 10%.
The break came in 1998. A Taiwanese student released CIH, a virus that overwrote the BIOS and could leave a machine unable to boot at all, and for the first three weeks of the outbreak Kaspersky's product was the only one that could remove it. That single fact produced licensing deals with antivirus companies in Japan, Finland and Germany, and revenue grew 280% between 1998 and 2000 with most of it coming from outside Russia.
**The research is the part of this company that its critics rarely dispute.** Its teams published on Stuxnet, Flame, Duqu, Red October, Equation Group and ProjectSauron - and the significance is who those operations are attributed to. Stuxnet and Flame are widely attributed to the United States and Israel; Equation Group's toolset was linked to American intelligence. A Russian company built much of its reputation by publishing detailed analysis of Western intelligence operations, while also publishing on Russian-attributed campaigns. Sergey Ulasen, working at a Belarusian firm later acquired into Kaspersky, is generally credited with first identifying Stuxnet.
**And then the other half, stated plainly.** On 13 September 2017 the US Department of Homeland Security prohibited Kaspersky products across federal agencies, alleging the company had worked on projects with Russia's Federal Security Service. In October 2017, press reports alleged that Russian government hackers had obtained classified material from a contractor's home computer running the software. On 20 June 2024 the US Commerce Department went further, prohibiting sale and use of the software in the United States, and the Treasury sanctioned company leadership. Germany's federal security office had warned against it in March 2022, and the United Kingdom and Australia have imposed restrictions of their own.
The company has denied intelligence ties consistently, describing the allegations as speculation without evidence, and has offered third-party source-code audits and transparency centres in an attempt to address them. Those measures have not changed any government's position.
**This page does not resolve that, because the public record does not.** What can be said is narrower and more useful: a security product requires more trust than almost any other software, because it runs with the highest privileges, sees everything on the machine, and updates itself continuously from its vendor. The SolarWinds and CrowdStrike entries on this timeline show what happens when that trust is misplaced by accident and by attack. A government reasoning about a vendor subject to a foreign legal system is reasoning about the same property - and it can reach a restrictive conclusion without any specific wrongdoing having been proven.
That is the genuinely instructive thing here, and it applies well beyond one company. **Jurisdiction is part of a product's threat model.** Where a vendor's engineers can be legally compelled, and by whom, is a security property of the software, and it is not visible in any feature comparison.
- Wikipedia: Kaspersky Lab - the four founders, the departure from KAMI, the AVP trademark rename, and the 1998 CIH outbreak in which its product was the only one able to remove the virus
- Wikipedia: Natalya Kaspersky - taking over distribution in September 1994, revenue from $100-200 a month to over $1M in 1997, launching the foundation in June 1997, naming the company, a decade as CEO, and the initial equity split
- Wikipedia: Eugene Kaspersky - the KGB Higher School cryptology faculty, the 1987 degree, Soviet military service, and the 1989 Cascade virus
- Wikipedia: Kaspersky bans and allegations of Russian government ties - the 13 September 2017 DHS directive, the October 2017 reports, and the German warning of March 2022, with the company's denials
- CNN: the 20 June 2024 US prohibition on sale and use, and the recognition of Kaspersky researchers as top-tier analysts of operations attributed to several governments including Russia, the US and Israel
- Kaspersky's own account of its research record, including Stuxnet, Flame and Red October