Citadel Trojan

By LoneStar in Trojans | 499 views
Rate it:
1 Star2 Stars3 Stars4 Stars5 Stars (1 votes, average: 5.00 out of 5)
Loading ... Loading ...
More... More

Citadel Trojan Description

Image Screenshot

[+] Click Image to Enlarge

The Citadel Trojan – A Version of the Infamous ZeuS Trojan

The Citadel Trojan first started making its rounds in early 2012 and gave the impression of having the same abilities as the infamous ZeuS Trojan. The ZeuS Trojan is one of the most notorious Trojan infections of the last decade. This Trojan has been known to steal banking information such as account numbers and passwords, as well as being linked to some of the most important botnets in recent years. Because of this, any sign of the Citadel Trojan on your computer system should be cause for concern – apart from treating the Citadel Trojan infection, ESG security analysts strongly recommend ensuring that your online bank accounts have not become compromised.

The Malware Makers Behind the Citadel Trojan Focus on Customer Service

It may sound strange, but support and customer service are also an important part of the hacking community. Criminals do not create malware like the Citadel Trojan in a vacuum. They can actually earn quite a lot of money by selling their malware creations to other criminals who can then use botnets and phishing scams to attempt to steal people’s banking credentials. Scouring forums and seedy websites linked to criminal activity, ESG malware analysts suspect that the Citadel Trojan seems to have been created as a ‘customer service’ oriented version of the ZeuS Trojan! One particularly clever aspect of the Citadel Trojan is the fact that Citadel Trojan is designed not to attack computers with a keyboard in Cyrillic characters (thus ensuring that the Russian or Ukrainian authorities will not see Citadel Trojan as a local threat).

The Citadel Trojan May Be the ZeuS Trojan’s First Direct Descendant

Since 2011, when the source code for the ZeuS Trojan was released and made available publicly, ESG security researchers have been concerned that various copycat infections may spring up, improving on the original and making this malware threat even more difficult to remove. The Citadel Trojan may be this dreaded descendant of the infamous banking Trojan. The creators of the Citadel Trojan advertise Citadel Trojan as containing various improvements and bug fixes as well as being able to attack various web browsers more effectively than before. The Citadel Trojan also contains a component that is able to record its victim’s activity and then send a video of the victim’s screen to a remote server where Citadel Trojan can then be viewed.

Type: Trojans

How Can You Detect Citadel Trojan?

Citadel Trojan Removal Details

Citadel Trojan creates the following files in the system:

  • %UserProfile%\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\dll.lnk
  • %UserProfile%\Start Menu\Programs\Startup\.dll.lnk
  • %AllUsersProfile%\Application Data\Citadel Trojan

Important Article Disclaimer

ESG Support Center

This entry was last updated on 09/28/12 and posted on 01/27/12. You can follow any responses to this entry through the RSS 2.0 feed. You can leave a response, or trackback from your own site.

Leave a Comment

Note: Abusive comments are not allowed. Please do not post comments regarding technical support issues. ESG customers that have issues with SpyHunter should open a customer support ticket.

*
To prove you're a person (not a spam script), type the security word shown in the picture. Click on the picture to hear an audio file of the word.
Click to hear an audio file of the anti-spam word

Home | SpyHunter Risk Assessment Model | Privacy Policy | End User License Agreement | Additional Terms and Conditions
Copyright 2003-2012. Enigma Software Group USA, LLC. All Rights Reserved.