Citadel crimeware kit to be pulled off the open market
Posted on 04.07.2012
The developers of the Citadel malware - a banking Trojan that is based on Zeus Trojan's source code and whose creators have adopted a Software-as-a-Service approach when it comes to the modifications of the crimeware kit that produces its variants - have announced that they will soon stop offering the malicious software on open underground markets.


First released on January 2012 into the Russian-speaking underground, the Citadel crimeware became extremely popular with online criminals in a very short time due to the continuos updating and the possibility for customers to contact the developers and ask for new capabilities via the malware's CRM.

"Sold for $2,500 for a kit with added plugins going for an average of $1,000 each, Citadel developers are making good money with this banking Trojan," RSA researchers point out.

But, as many other malware developers before them, they seem increasingly concerned with the attention their malware and the criminals using it are getting from law enforcement agencies, and this could explain the announcement.

Still, it appears that existing customers will still get the upgrades, and be able to vouch for new customers.

"While this could be a marketing stint designed to create urgency and generate more sales, Citadelís developers could also be seeing the need to slow down sales. By selling less they can keep the Trojan from being all too widely-spread, which will invariably lead to more sampling and research and cause them the need to rework its evasion mechanisms," say the researchers.

"Additionally, more customers also means more support, more underground buzz, and eventually, like Zeus, SpyEye, and Carberp ó more cybercrime arrests linked with using Citadel."






Spotlight

Windows 0-day exploited in ongoing attacks, temporary workarounds offered

Posted on 22 October 2014.  |  A new Windows zero-day vulnerability is being actively exploited in the wild and is primarily a risk to users on servers and workstations that open documents with embedded OLE objects.


Weekly newsletter

Reading our newsletter every Monday will keep you up-to-date with security news.
  



Daily digest

Receive a daily digest of the latest security news.
  

DON'T
MISS

Thu, Oct 23rd
    COPYRIGHT 1998-2014 BY HELP NET SECURITY.   // READ OUR PRIVACY POLICY // ABOUT US // ADVERTISE //