Seems plausible, though regardless of whether Kaspersky cooperates (maybe under some gag order) with Russian agencies or not, it seems prudent for any government in the world to avoid using software that potentially uploads confidential data to foreign servers. Governments anywhere would probably be ill-advised to use anti-virus software from countries like the US or Russia, unless they can be sure that cloud analysis is either disabled or done in local datacenters.
I guess on the bright side at least the anti-virus market has a variety of firms based in many different countries, so you can choose your poison based on how trustworthy you find the respective governments. Doesn't help you when they themselves get hacked though.
As for the story itself, I kinda dislike the reliance on access journalism and "unnamed" sources in many of the reports. Yes, there surely are many legitimate reasons why sources have to remain anonymous, no doubt about that. But in a case that's so highly political it kinda leaves a bad taste if the story is so dependent on unnamed government sources.