- Citadel is a banking trojan that was first discovered in 2012. It is based on the source code of the Zeus trojan.
- This trojan is designed to steal sensitive information including financial data and passwords.
Citadel is known for targeted attacks on public and private organizations, stealing credentials for various information management systems, money , and also infecting systems with a range of malware. In fact, this is one of the first trojans to deliver malware on the dark web.

The capabilities of Citadel
Using the man-in-the-browser (MiTB) technique, which involves injecting HTML or JavaScript into a web page, this trojan collects sensitive information.
- MiTB allows hackers to add additional fields to the website, such as the PIN number or other sensitive fields.
- Users assume they are entering details on a legitimate website, but they fall victim to credential theft by this trojan.
- The malicious software also has keylogging capabilities that can put passwords and authentication systems at risk.
- In some attacks, the infected systems were observed turning into bots in a botnet.
- A ransomware called Reveton was also used in some attacks, suggesting that the FBI imposed a blockade and demanded a ransom amount.
Attacks in the foreground
Citadel and its variants are said to have infected millions of computers and caused massive financial losses.
January 2014: It was reported that the infamous Target breach of 2013 involved the Citadel Trojan.
February 2013: NBC's website was hacked and redirected visitors to the Citadel banking Trojan. The site is said to host an iframe that led visitors to sites hosted by the RedKit exercise kit, which served the malware.
September 2014: Researchers discovered a variant of the Trojan used in attacks against several petrochemical companies in the Middle East. This was likely the first time Citabel was used in attacks against non-financial entities in targeted attacks.
April 2016: A new malicious software branch called Atmos, a variant of Citadel, was discovered. Researchers observed that it had the same motives as the Citadel Trojan.
The developers of Citadel went to prison
Dimitry Belorossov was sentenced to four years and six months in prison for distributing and installing the Citadel trojan. Mark Vartanyan, who was accused of developing the Citadel trojan, received a five‑year prison sentence.
