Citadel

First seen
2011-12-01 00:00:00
Malware type
botnet, credential-stealer, keylogger
Family
Malware family
Last IoC activity
2026-07-22 00:32:41
Profile updated
2026-07-07 14:34:10

Targeted industries: financial-services

Targeted regions: country_code:us country_code:gb country_code:de country_code:fr country_code:ca

Context

Citadel is a banking trojan and botnet malware that primarily targets financial institutions. It is known for stealing online banking credentials and has been used to facilitate financial fraud. Developed as a successor to the Zeus trojan, Citadel has affected multiple countries worldwide.

Detection coverage

  • 1 YARA rules

Detection rules

  • MALPEDIA_Win_Citadel_Auto (yara-rule)

Reports & references

  • malware.dontneedcoffee.com — Eyeglanceru (report)
  • f5.com — Banking Trojans A Reference Guide To The Malware Family Tree (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Citadel (report)
  • vx-underground.org — Money%20Taker (report)
  • blog.jpcert.or.jp — Banking Trojan 27D6 (report)
  • xylibox.com — Citadel 0011 Atmos (report)
  • blog.malwarebytes.com — Citadel A Cyber Criminals Ultimate Weapon (report)
  • justice.gov — Four Individuals Plead Guilty Rico Conspiracy Involving Bulletproof Hosting Cybercriminals (report)

External references