Citadel developer banned from crime forum

Powered by SC Magazine
 

RSA says the ousting of Aquabox is just the latest indication that the Citadel network is headed further underground.

A key Citadel developer has been banned from one of the largest online sites that sells the banking trojan.

Experts say it is another sign that Citadel developers are steadily withdrawing from the commercial market to privatise their operations.

The developer, “Aquabox,” was banned from an online forum after a Citadel buyer accused him of “becoming corrupt by all the money Citadel was earning him,” according to RSA.

Citadel's sellers began threatening to pull the Zeus variant off the open market in July to fend off interference by law enforcement. The trojan entered the market in January, selling for $2,399, and as of October, the sixth edition cost $3,391.

Citadel, along with other banking trojans, usually infects users through spam messages or via drive-by download campaigns.

Banking malware often aims to steal account login credentials to transfer money to attackers, either in the background or by hijacking victims' computers.

RSA researchers said that Aquabox's departure from the online community demonstrated the Citadel network's decision to become more covert.

“The recent accusations against Aquabox are only one of many hints that confirm the very imminent withdrawal of the Citadel trojan, as its developers change their business model from offering it as commercially available crimeware to a much more selective and privatized operation,” the blog post said.

RSA said that the Citadel network moving further underground likely meant that Citadel variants would become more contained – at first. However, over time, fewer samples available to researchers could mean lowered detection rates.

“Although the Citadel developers are not as interested in new buyers today, the team may still return to cybercrime forums or devise another business model in an effort to return with more news in the future,” the post said.

The malware remains active. Late last month, the Internet Crime Complaint Center (IC3) issued a warning that cyber criminals were using the Citadel trojan to, in turn, infect users with Reveton ransomware.

This article originally appeared at scmagazineus.com

Copyright © SC Magazine, US edition


Citadel developer banned from crime forum
 
 
 
Top Stories
Innovating in the sleepy super industry
There’s little incentive to be on the bleeding edge, so why is Andrew Todd fighting so hard?
 
How technology will unify Toll
The systems headache formed through 15 years of acquisitions.
 
Immigration breached Privacy Act with data leak
Pilgrim slams "copy and paste" of asylum seeker data.
 
 
Sign up to receive iTnews email bulletins
   FOLLOW US...
Latest Comments
Polls
Who do you trust most to protect your private data?







   |   View results
Your bank
  39%
 
Your insurance company
  3%
 
A technology company (Google, Facebook et al)
  7%
 
Your telco, ISP or utility
  8%
 
A retailer (Coles, Woolworths et al)
  2%
 
A Federal Government agency (ATO, Centrelink etc)
  20%
 
An Australian law enforcement agency (AFP, ASIO et al)
  15%
 
A State Government agency (Health dept, etc)
  5%
TOTAL VOTES: 823

Vote