Citadel Trojan: Open-Source Malware Community Adds Customer Care

The developers of Citadel, a new variant of the infamous Zeus Trojan, have adopted Software-as-a-Service (SaaS) and open-source models, allowing them to create malware with advanced features.

According to a report on Seculert blog, the team of developers went as far as creating a dedicated social network, which enables other cybercriminals to suggest new features and modules to the malware, report bugs and other errors in the system and even comment and discuss related issues with fellow “customers”.

Organising crime

Since Zeus source-code went public in 2011, the Citadel community became very active, and started contributing new modules and features to the malware.

Seculert’s Research Lab discovered the first indication of a Citadel botnet on 17 December, 2011. The level of adoption and development of the Trojan is rapidly growing and, since then, Seculert has identified over 20 different Citadel botnets.

Each successive version has added new modules and features, some of which were submitted by the Citadel customers themselves, including improved encryption, better tracker avoidance, and trigger-based video recording.

One of the most worrying features is a security vendor blacklist, which means that, once infected, the computer will be unable to download anti-virus software or updates.

Similar to legitimate software companies, the Citadel authors provide their customers with a user manual, release notes and a licence agreement.

In an online posting, discovered by security blogger Brian Krebs, Citadel’s developers claimed: “It’s no secret that the products in our field — without support from the developers — result in a piece of junk on your hard drive. Therefore, the product should be improved according to the wishes of our customers.”

Several experts agree that the open-source model may be the next growing trend in cybercrime. If this turns out to be true, IT sector might have to deal with cutting-edge, constantly evolving malware, designed by hundreds of people. And that is not a great prospect.

Max Smolaks

Max 'Beast from the East' Smolaks covers open source, public sector, startups and technology of the future at TechWeekEurope. If you find him looking lost on the streets of London, feed him coffee and sugar.

Recent Posts

SoftBank Promises To Invest $100bn In US

Japanese tech investment firm SoftBank promises to invest $100bn during Trump's second term to create…

4 hours ago

Synopsys, SiMa.ai To Collaborate On AI Car Chips

Synopsys to work with start-up SiMa.ai on joint offering to help accelerate development of AI…

5 hours ago

AI Start-Up Basis Raises $34m For Accountancy Agent

Start-up Basis raises $34m in Series A funding round for AI-powered accountancy agent to make…

5 hours ago

Databricks Raises $10bn In Huge AI Funding Round

Data analytics and AI start-up Databricks completes huge $10bn round from major venture capitalists as…

6 hours ago

Congo Files Complaints Against Apple Over Conflict Minerals

Congo files legal complaints against Apple in France, Belgium alleging company 'complicit' in laundering conflict…

6 hours ago

EU Opens TikTok Probe Over Election Interference Claims

European Commission opens formal probe into TikTok after Romanian first-round elections annulled over Russian interference…

7 hours ago