iTnews
  • Home
  • News
  • Technology
  • Security

Citadel developer banned from crime forum

By Danielle Walker on Dec 13, 2012 8:21AM
Citadel developer banned from crime forum

RSA says the ousting of Aquabox is just the latest indication that the Citadel network is headed further underground.

A key Citadel developer has been banned from one of the largest online sites that sells the banking trojan.

Experts say it is another sign that Citadel developers are steadily withdrawing from the commercial market to privatise their operations.

The developer, “Aquabox,” was banned from an online forum after a Citadel buyer accused him of “becoming corrupt by all the money Citadel was earning him,” according to RSA.

Citadel's sellers began threatening to pull the Zeus variant off the open market in July to fend off interference by law enforcement. The trojan entered the market in January, selling for $2,399, and as of October, the sixth edition cost $3,391.

Citadel, along with other banking trojans, usually infects users through spam messages or via drive-by download campaigns.

Banking malware often aims to steal account login credentials to transfer money to attackers, either in the background or by hijacking victims' computers.

RSA researchers said that Aquabox's departure from the online community demonstrated the Citadel network's decision to become more covert.

“The recent accusations against Aquabox are only one of many hints that confirm the very imminent withdrawal of the Citadel trojan, as its developers change their business model from offering it as commercially available crimeware to a much more selective and privatized operation,” the blog post said.

RSA said that the Citadel network moving further underground likely meant that Citadel variants would become more contained – at first. However, over time, fewer samples available to researchers could mean lowered detection rates.

“Although the Citadel developers are not as interested in new buyers today, the team may still return to cybercrime forums or devise another business model in an effort to return with more news in the future,” the post said.

The malware remains active. Late last month, the Internet Crime Complaint Center (IC3) issued a warning that cyber criminals were using the Citadel trojan to, in turn, infect users with Reveton ransomware.

This article originally appeared at scmagazineus.com

Got a news tip for our journalists? Share it with us anonymously here.
Copyright © SC Magazine, US edition
Tags:
citadelmalwarersasecurity

Partner Content

How to turn digital complexity into competitive advantage
Promoted Content How to turn digital complexity into competitive advantage
Accenture and Google Cloud team up to create a loveable, Australian-first, renewable energy product
Promoted Content Accenture and Google Cloud team up to create a loveable, Australian-first, renewable energy product
Why Genworth Australia embraced low-code software development
Promoted Content Why Genworth Australia embraced low-code software development
Avoiding CAPEX by making on-premise IT more cloud-like
Promoted Content Avoiding CAPEX by making on-premise IT more cloud-like

Sponsored Whitepapers

Extracting the value of data using Unified Observability
Extracting the value of data using Unified Observability
Planning before the breach: You can’t protect what you can’t see
Planning before the breach: You can’t protect what you can’t see
Beyond FTP: Securing and Managing File Transfers
Beyond FTP: Securing and Managing File Transfers
NextGen Security Operations: A Roadmap for the Future
NextGen Security Operations: A Roadmap for the Future
Video: Watch Juniper talk about its Aston Martin partnership
Video: Watch Juniper talk about its Aston Martin partnership

Events

  • CRN Channel Meets: CyberSecurity Live Event
  • IoT Insights: Secure By Design for manufacturing
  • Cyber Security for Government Summit
By Danielle Walker
Dec 13 2012
8:21AM
0 Comments

Related Articles

  • Global police operation takes down Flubot infrastructure
  • VMware, F5, Log4j added to EnemyBot attack targets
  • Google adds phishing protection to Workspace apps
  • FBI Cyclops Blink operation disinfected thousands of WatchGuard appliances
Share on Twitter Share on Facebook Share on LinkedIn Share on Whatsapp Email A Friend

Most Read Articles

Qantas calls time on IBM, Fujitsu in tech modernisation

Qantas calls time on IBM, Fujitsu in tech modernisation

Service NSW hits digital services goal two years early

Service NSW hits digital services goal two years early

SA Police ignores Adelaide council plea for facial recognition ban on CCTV

SA Police ignores Adelaide council plea for facial recognition ban on CCTV

NBN Co says TPG tie-up could help Telstra sidestep spectrum limits

NBN Co says TPG tie-up could help Telstra sidestep spectrum limits

Digital Nation

Integrity, ethics and board decisions in the digital age
Integrity, ethics and board decisions in the digital age
IBM global chief data officer on the rise of the number crunchers
IBM global chief data officer on the rise of the number crunchers
Crypto experts optimistic about future of Bitcoin: Block
Crypto experts optimistic about future of Bitcoin: Block
The security threat of quantum computing
The security threat of quantum computing
COVER STORY: Operationalising net zero through the power of IoT
COVER STORY: Operationalising net zero through the power of IoT
All rights reserved. This material may not be published, broadcast, rewritten or redistributed in any form without prior authorisation.
Your use of this website constitutes acceptance of nextmedia's Privacy Policy and Terms & Conditions.