Providing Free and Editor Tested Software Downloads
< HOME | TUTORIALS | GEEK-CADE| WEB TOOLS | YOUTUBE | NEWSLETTER | DEALS! | FORUMS | >

MajorGeeks.com - What about a nice warm cup of Geek?

Software Categories

All In One Tweaks
Android
Antivirus & Malware
Appearance
Back Up
Browsers
CD\DVD\Blu-Ray
Covert Ops
Drivers
Drives (SSD, HDD, USB)
Games
Graphics & Photos
Internet Tools
Linux Distros
MajorGeeks Windows Tweaks
Multimedia
Networking
Office & Productivity
System Tools

Other news

· How To and Tutorials
· Life Hacks and Reviews
· Way Off Base
· MajorGeeks Deals
· News
· Off Base
· Reviews




spread the word

· YouTube
· Facebook
· Instagram
· Twitter
· Pintrest
· RSS/XML Feeds
· News Blur
· Yahoo
· Symbaloo

about

· Top Freeware Picks
· Malware Removal
· Geektionary
· Useful Links
· About Us
· Copyright
· Privacy
· Terms of Service
· How to Uninstall

top downloads

1. GS Auto Clicker
2. Macrium Reflect FREE Edition
3. Smart Defrag
4. Visual C++ Redistributable Runtimes AIO Repack
5. Visual C++ Runtime Installer (All-In-One)
6. McAfee Removal Tool (MCPR)
7. MusicBee
8. Rufus
9. K-Lite Mega Codec Pack
10. Sergei Strelec's WinPE
More >>

top reads

Star How to Disable 1-Click Ordering on Amazon (and Avoid Surprise Charges)

Star How to Fix Shallow Paint Layer Depth in Bambu Studio

Star Aviator Betting Game Secrets: Unlock 97% RTP & Triple Your Wins

Star Windows Recall: What It Is, Why Hackers Will Love It, and How to Stay Safe

Star Star Trek Fleet Command Promo Codes: Redeem Codes for Free Shards, Blueprints And Resources

Star How To Use VLC Media Player to Trim Video Clips

Star What Is the $WinREAgent Folder and Can I Delete It?

Star Swear Your Way to Better Search Results

Star How to Get a Dark Start Menu and Taskbar in Windows 10 & 11

Star Enable, Disable, Manage, Delete or Create a System Restore Point


MajorGeeks.Com » News » July 2013 » Citadel virus still active

Citadel virus still active


Posted by: TimW on 07/03/2013 02:52 PM [ comments Comments ]


We reported a little while back about the government and Microsoft taking down approximately 12,000 Citadel botnets.

A new variant has popped up in the last few weeks targeting not only banks and financial institutions, but social networks and ecommerce websites such as Amazon. The malware triggers on infected machines when it browses to the target site and delivers an HTML injection that looks like a legitimate log-on page. The injection screen contains detailed localized content, specializing in Italian, Spanish, French, German, British, American and Australian targets for each brand in question.

“We did see a lot of effort to create custom scripts per local infection. The dropdowns are localized and there are specific data elements for different geographies,” said Etay Maor, Trusteer fraud prevention solutions manager. “This group localized things a person from a specific country would expect to see. They went to great effort to localize this.”

“They have a different way of storing data and have built databases for regions. That makes me think they’re going to sell the information rather than use it,” Maor said. Localized credentials, for example, have more value than a scattered list of user names and passwords. “For people who sell credentials, it’s a big difference to say they have 100 Italian credentials. For example, it doesn’t help to have American account information if you’re working in Italy. You can use it, but you need an accomplice who knows the local rules.”

“What we’ve seen is an interesting group, a low-profile team. This variant is not sold as we’ve seen other variants sold,” Maor said. “The distribution isn’t huge, but it is significant. They’re very good at protecting stored stolen credentials, and very good at making the malware hard to research. These are not your average hackers; they didn’t just buy a version of the Citadel malware. They took the extra step to make it covert and sustainable, and to localize it.”

“You can see the injections are professional. There are no grammar mistakes and the logos all look real,” Maor said, adding that victims are likely infected via drive-by downloads. “But if you log into Amazon and you see a screen you’ve never seen before, even one that warns you that your account will be shut down, you should be a little more skeptical.”

“They disrupted more than 1,000 botnets operated by Citadel, but it’s important that people understand that while the operation was important, it didn’t solve the problem,” Maor said. “They disrupted botnets that were up and running, but anyone who has the Citadel builder can build a new variant and distribute it. They didn’t eliminate Citadel. Yeah, business took a hit, but it can be recreated.”




« Malware that creates a download loop · Citadel virus still active · Skype users troll witness during Zimmerman trial »




Comments
comments powered by Disqus

MajorGeeks.Com » News » July 2013 » Citadel virus still active

© 2000-2025 MajorGeeks.com
Powered by Contentteller® Business Edition