Citadel

Last reviewed:

Citadel is a type of malware that emerged as a sophisticated banking Trojan. It is designed to steal sensitive financial information from infected systems. Citadel is a derivative of the Zeus malware, which is known for its capability to capture keystrokes and exfiltrate data. As of October 2023, Citadel has been involved in numerous cybercriminal activities, primarily targeting financial institutions and their customers. This article provides a comprehensive overview of Citadel, its history, technical characteristics, infection vectors, notable campaigns, and methods for detection and mitigation.

Overview

Citadel is a banking Trojan that primarily targets financial institutions and their customers. It is a variant of the Zeus malware family, which is known for its capabilities in stealing sensitive information such as login credentials and financial data. Citadel is distributed through various infection vectors, including phishing emails and exploit kits. It has been used in numerous cybercriminal campaigns worldwide, causing significant financial losses.

History

Citadel first appeared in the cybercriminal landscape around 2011. It was initially developed as an improved version of the Zeus Trojan, with enhancements in its functionality and evasion techniques. The malware was sold on underground forums, allowing cybercriminals to customize and deploy it for their specific needs. Over the years, Citadel has been involved in several high-profile campaigns, targeting financial institutions and other organizations.

Technical characteristics

Citadel is designed to steal sensitive information from infected systems. It achieves this through various techniques, including keylogging, form grabbing, and screen capturing. The malware is highly configurable, allowing attackers to customize its functionality according to their needs. Citadel also includes features for evading detection, such as encryption and obfuscation of its code. Additionally, it can disable security software and establish persistence on infected systems.

Infection vector

Citadel is primarily distributed through phishing emails and exploit kits. Phishing emails often contain malicious attachments or links that, when opened, download and execute the Citadel malware on the victim's system. Exploit kits are used to deliver the malware by exploiting vulnerabilities in software such as web browsers and plugins. Once the malware is installed, it begins its operation of stealing sensitive information.

Notable campaigns

Citadel has been involved in several notable cybercriminal campaigns. One of the most significant campaigns occurred in 2012, when Citadel was used to target financial institutions in Europe and the United States. The malware was responsible for stealing millions of dollars from bank accounts. In another campaign, Citadel was used to target government agencies and critical infrastructure, highlighting its versatility and potential impact.

Detection and mitigation

Detecting Citadel involves monitoring for indicators of compromise, such as unusual network traffic and unauthorized access attempts. Security software can help identify and remove the malware from infected systems. Mitigation strategies include implementing strong email filtering to prevent phishing attacks, keeping software up to date to protect against exploit kits, and educating users about safe online practices. Regular security audits and network monitoring can also help detect and respond to Citadel infections.

History of Citadel Malware

Infection Vectors of Citadel

See also

- Zeus malware
- Banking Trojan
- Phishing
- Exploit kits

Sources

- MITRE ATT&CK - Citadel
- CISA - Citadel Malware
- Securelist - Citadel Trojan

This article provides an overview of the Citadel malware, its history, technical characteristics, infection vectors, notable campaigns, and methods for detection and mitigation. It is important for organizations to remain vigilant and implement robust security measures to protect against threats like Citadel.

Categories: Malware
Last updated: August 26, 2026