Citadel
Citadel is a Windows banking Trojan derived from Zeus and first identified in 2011.
Citadel
Family profile
Citadel is a Windows banking Trojan derived from Zeus and first identified in 2011. It is used by financially motivated cybercriminals to harvest credentials and facilitate fraudulent transactions against online banking customers worldwide. Its capabilities include keylogging, credential theft targeting password managers, browser web injections, and video capture of the victim’s screen. Citadel-compatible web injections support automated banking fraud, while screen recording gives operators visibility into victims’ banking activity. The malware also employs defense-evasion techniques to hinder detection.
Citadel has operated through criminal botnets and infrastructure supplied by bulletproof hosting providers. Its campaigns have affected companies and financial institutions, including U.S. victims. It has also been distributed alongside Reveton ransomware in drive-by infection campaigns; Citadel’s banking and credential-theft functions are distinct from Reveton’s screen-locking extortion behavior. In 2013, Microsoft’s Digital Crimes Unit coordinated with the FBI to disrupt Citadel botnets under a civil seizure order.
Capabilities
- Credential Theft
- Defense Evasion
- Keylogging
Samples
Recent samples
1 sandbox sample in the Derp library, newest 1 shown
Exploited software
Vulnerabilities linked to Citadel
7 CVEsMITRE ATT&CK
Citadel in ATT&CK
33 distinct techniquesReporting