Citadel
- First seen
- 2011-12-01 00:00:00
- Malware type
- botnet, credential-stealer, keylogger
- Family
- Malware family
- Last IoC activity
- 2026-07-22 00:32:41
- Profile updated
- 2026-07-07 14:34:10
Targeted industries: financial-services
Targeted regions: country_code:us country_code:gb country_code:de country_code:fr country_code:ca
Context
Citadel is a banking trojan and botnet malware that primarily targets financial institutions. It is known for stealing online banking credentials and has been used to facilitate financial fraud. Developed as a successor to the Zeus trojan, Citadel has affected multiple countries worldwide.
Detection coverage
- 1 YARA rules
Detection rules
- MALPEDIA_Win_Citadel_Auto (yara-rule)
Reports & references
- malware.dontneedcoffee.com — Eyeglanceru (report)
- f5.com — Banking Trojans A Reference Guide To The Malware Family Tree (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Citadel (report)
- vx-underground.org — Money%20Taker (report)
- blog.jpcert.or.jp — Banking Trojan 27D6 (report)
- xylibox.com — Citadel 0011 Atmos (report)
- blog.malwarebytes.com — Citadel A Cyber Criminals Ultimate Weapon (report)
- justice.gov — Four Individuals Plead Guilty Rico Conspiracy Involving Bulletproof Hosting Cybercriminals (report)