Security Experts:

Connect with us

Hi, what are you looking for?


Malware & Threats

RSA: Citadel Developer Banned From Cyber Underground Forum

Researchers at EMC’s RSA security division say evidence that the Citadel Trojan is slowly being pulled from underground markets continues to pile up.

Researchers at EMC’s RSA security division say evidence that the Citadel Trojan is slowly being pulled from underground markets continues to pile up.

According to RSA, a recent spat between Citadel’s developer, known as “Aquabox”, and one of his buyers led to him being banned from one of the “largest online crime communities Citadel was ever a part of.” The buyer accused Aquabox of becoming corrupt by all the money Citadel had earned him.

“The recent accusations against Aquabox are only one of many hints that confirm the very imminent withdrawal of the Citadel Trojan, as its developers change their business model from offering it as commercially-available crimeware to a much more selective and privatized operation,” according to a blog post today by RSA FraudAction Research Labs.

In July, RSA reported that it had found a statement on an underground forum that said updates for the Trojan would no longer be publicly available, and that only existing customers would be receiving upgrades. Others who wanted to purchase a new kit were told they would have to get an existing customer to vouch for them.

There are a number of reasons Citadel’s developers may want to go private. The more readily available Citadel is, the more likely it will attract law enforcement attention, RSA noted. In addition, with some many customers, technical support can be challenging.

Finally, the team may wish to go back to focusing on other endeavors, such as fraud.

“Citadel being taken deeper underground will likely mean a smaller, less “public” deployment of this Trojan, which could in turn result in the proliferation of Citadel variants becoming stabilized,” according to RSA. “It may also mean that in the long run detection rates (by AV engines) will gradually drop due to more limited sampling opportunities.

“Although the Citadel developers are not as interested in new buyers today, the team may still return to cybercrime forums or devise another business model in an effort to return with more news in the future.”

Written By

Click to comment

Expert Insights

Related Content

Malware & Threats

Microsoft plans to improve the protection of Office users by blocking XLL add-ins from the internet.


CISA, NSA, and MS-ISAC issued an alert on the malicious use of RMM software to steal money from bank accounts.


A recently disclosed vBulletin vulnerability, which had a zero-day status for roughly two days last week, was exploited in a hacker attack targeting the...


Chinese threat actor DragonSpark has been using the SparkRAT open source backdoor in attacks targeting East Asian organizations.


Russia-linked cyberespionage group APT29 has been observed using embassy-themed lures and the GraphicalNeutrino malware in recent attacks.

Malware & Threats

Security researchers are warning of a new wave of malicious NPM and PyPI packages designed to steal user information and download additional payloads.


No one combatting cybercrime knows everything, but everyone in the battle has some intelligence to contribute to the larger knowledge base.

Malware & Threats

Cybercrime in 2017 was a tumultuous year "full of twists and turns", with new (but old) infection methods, a major return to social engineering,...