Providing Free and Editor Tested Software Downloads
< HOME | TUTORIALS | GEEK-CADE| WEB TOOLS | YOUTUBE | NEWSLETTER | DEALS! | FORUMS | >

Just when you thought things couldn't get Geekier - MajorGeeks.Com.

Software Categories

All In One Tweaks
Android
Antivirus & Malware
Appearance
Back Up
Browsers
CD\DVD\Blu-Ray
Covert Ops
Drivers
Drives (SSD, HDD, USB)
Games
Graphics & Photos
Internet Tools
Linux Distros
MajorGeeks Windows Tweaks
Multimedia
Networking
Office & Productivity
System Tools

Other news

· How To and Tutorials
· Life Hacks and Reviews
· Way Off Base
· MajorGeeks Deals
· News
· Off Base
· Reviews


Opera One
Everything
you need.
Already
there.
AI assistant
Aria, built right in
Free VPN
No account needed
Ad blocker
Faster, cleaner web
Tab Islands
Grouped browsing
Useful sidebars
Make it yours
No Clunky Extensions Needed.



MajorGeeks Approved.



Download free

spread the word

· YouTube
· Facebook
· Instagram
· Twitter
· Pintrest
· RSS/XML Feeds
· News Blur
· Yahoo
· Symbaloo

about

· Top Freeware Picks
· Malware Removal
· Geektionary
· Useful Links
· About Us
· Copyright
· Privacy
· Terms of Service
· How to Uninstall

top downloads

1. GS Auto Clicker
2. Smart Defrag
3. Macrium Reflect FREE Edition
4. K-Lite Mega Codec Pack
5. MusicBee
6. Microsoft Visual C++ 2015-2022 Redistributable Package
7. Sergei Strelec's WinPE
8. K-Lite Codec Pack Full
9. Visual C++ Redistributable Runtimes AIO Repack
10. McAfee Removal Tool (MCPR)
More >>

top reads

Star How Much Storage Space Are Your Installed Apps Using in Windows 11?

Star How To Reset and Fix the Settings App in Windows 11

Star How To Remove the Windows 11 Updated Start Menu

Star How To Download a Windows 11 ISO

Star How To Disable Drag Tray

Star How To Boot Into WinRE (Windows Recovery Environment)

Star How To Find the Installation Date of Apps

Star Recently Opened Files - How To Hide or Show Them In Jump Lists, File Explorer, and Start Menu

Star How To Change the Name of a Local or Microsoft Account

Star How To Remove OneDrive From the Navigation Pane in File Explorer


MajorGeeks.Com » News » July 2013 » Citadel virus still active

Citadel virus still active


Posted by: TimW on 07/03/2013 10:52 AM [ comments Comments ]


We reported a little while back about the government and Microsoft taking down approximately 12,000 Citadel botnets.

A new variant has popped up in the last few weeks targeting not only banks and financial institutions, but social networks and ecommerce websites such as Amazon. The malware triggers on infected machines when it browses to the target site and delivers an HTML injection that looks like a legitimate log-on page. The injection screen contains detailed localized content, specializing in Italian, Spanish, French, German, British, American and Australian targets for each brand in question.

“We did see a lot of effort to create custom scripts per local infection. The dropdowns are localized and there are specific data elements for different geographies,” said Etay Maor, Trusteer fraud prevention solutions manager. “This group localized things a person from a specific country would expect to see. They went to great effort to localize this.”

“They have a different way of storing data and have built databases for regions. That makes me think they’re going to sell the information rather than use it,” Maor said. Localized credentials, for example, have more value than a scattered list of user names and passwords. “For people who sell credentials, it’s a big difference to say they have 100 Italian credentials. For example, it doesn’t help to have American account information if you’re working in Italy. You can use it, but you need an accomplice who knows the local rules.”

“What we’ve seen is an interesting group, a low-profile team. This variant is not sold as we’ve seen other variants sold,” Maor said. “The distribution isn’t huge, but it is significant. They’re very good at protecting stored stolen credentials, and very good at making the malware hard to research. These are not your average hackers; they didn’t just buy a version of the Citadel malware. They took the extra step to make it covert and sustainable, and to localize it.”

“You can see the injections are professional. There are no grammar mistakes and the logos all look real,” Maor said, adding that victims are likely infected via drive-by downloads. “But if you log into Amazon and you see a screen you’ve never seen before, even one that warns you that your account will be shut down, you should be a little more skeptical.”

“They disrupted more than 1,000 botnets operated by Citadel, but it’s important that people understand that while the operation was important, it didn’t solve the problem,” Maor said. “They disrupted botnets that were up and running, but anyone who has the Citadel builder can build a new variant and distribute it. They didn’t eliminate Citadel. Yeah, business took a hit, but it can be recreated.”




« Malware that creates a download loop · Citadel virus still active · Skype users troll witness during Zimmerman trial »




Comments
comments powered by Disqus

MajorGeeks.Com » News » July 2013 » Citadel virus still active

© 2000-2026 MajorGeeks.com
Powered by Contentteller® Business Edition