Malware

Atmos, the Citadel Trojan successor is in the wild

Security experts from the Heimdal Security firm are issuing an alert on the Atmos malware which is the successor of the dreaded Citadel Trojan.

Months ago, the author of the dreaded Citadel malware was sentenced to prison, but in the same period, a new improved variant resurged in the wild. The new strain of Citadel malware, called Atmos, is now targeting banks in France and it was also served with the Teslacrypt ransomware.

Atmos has been active since late 2015, but the experts have discovered it in the wild only recently.

Citadel was first spotted in 2011, its authors used the code of the ZeuS Trojan code to create the new threat.

“Dimitry Belorossov, a/k/a Rainerfox, has been sentenced to four years, six months in prison following his guilty plea for conspiring to commit computer fraud. Belorossov distributed and installed Citadel, a sophisticated malware that infected over 11 million computers worldwide, onto victim computers using a variety of infection methods.” stated the announcement issued by the FBI.

“In 2012, Belorossov downloaded a version of Citadel, which he then used to operate a Citadel botnet primarily from Russia. Belorossov remotely controlled over 7,000 victim bots, including at least one infected computer system with an IP address resolving to the Northern District of Georgia. Belorossov’s Citadel botnet contained personal information from the infected victim computers, including online banking credentials for U.S.-based financial institutions with federally insured deposits, credit card information, and other personally identifying information.”

The Citadel malware is a powerful data stealer, it was mainly used in banking frauds, but it has the ability to carry out a large number of fraudulent operations.

In the second half of 2012, security experts began to see Citadel variants designed to breach networks of  government and private companies.

On June 5 2013, the Microsoft Digital Crimes Unit announced that its experts were working with the FBI to shut down the Citadel botnet and to arrest its operators.

Today security experts at Heimdal security are issuing an alert on the Citadel successor, Atmos.

The researchers discovered that the new Citadel variant was heavily modified respect its predecessors. It utilizes the same web injection mechanisms implemented by ZeuS, a circumstance that leads the experts into belief that it was designed with the same intent.

The researchers confirmed that only a few sample was discovered in the wild targeting French banks.

Giving a look at the technical details shared by the Heimdal Security, we note that C&C servers are located in Vietnam, Canada, Ukraine, Russia, the US and Turkey and the overall Atom botnet is already composed of more than 1000 machines.

Below the list of Indicators of Compromise tied to the new Atmos Trojan:

http://iguana58[.]ru/plugins/system/anticopy/adobe[.]exe
http://tehnoart[.]co/sr[.]exe
http://3dmaxkursum[.]net/tmp/sys/config[.]exe
http://iguana58[.]ru/plugins/system/anticopy/adobe[.]exe
http://mareikes[.]com/wp-includes/pomo/svhost[.]exe
http://mareikes[.]com/wp-includes/pomo/server[.]exe

I invite you to read the Heimdal’s Alert, Atmos have to be considered a very dangerous threat, especially for the private industry.

[adrotate banner=”9″]

Pierluigi Paganini 

(Security Affairs – Atmos trojan, Citadel)

Pierluigi Paganini

Pierluigi Paganini is member of the ENISA (European Union Agency for Network and Information Security) Threat Landscape Stakeholder Group and Cyber G7 Group, he is also a Security Evangelist, Security Analyst and Freelance Writer. Editor-in-Chief at "Cyber Defense Magazine", Pierluigi is a cyber security expert with over 20 years experience in the field, he is Certified Ethical Hacker at EC Council in London. The passion for writing and a strong belief that security is founded on sharing and awareness led Pierluigi to find the security blog "Security Affairs" recently named a Top National Security Resource for US. Pierluigi is a member of the "The Hacker News" team and he is a writer for some major publications in the field such as Cyber War Zone, ICTTF, Infosec Island, Infosec Institute, The Hacker News Magazine and for many other Security magazines. Author of the Books "The Deep Dark Web" and “Digital Virtual Currency and Bitcoin”.

Recent Posts

SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 46

Security Affairs Malware newsletter includes a collection of the best articles and research on malware…

13 hours ago

Security Affairs newsletter Round 525 by Pierluigi Paganini – INTERNATIONAL EDITION

A new round of the weekly Securitythe weekly Security Affairs newsletterAffairs newsletter arrived! Every week…

13 hours ago

Operation ENDGAME disrupted global ransomware infrastructure

Operation ENDGAME dismantled key ransomware infrastructure, taking down 300 servers, 650 domains, and seizing €21.2M…

16 hours ago

Silent Ransom Group targeting law firms, the FBI warns

FBI warns Silent Ransom Group has targeted U.S. law firms for 2 years using callback…

1 day ago

Leader of Qakbot cybercrime network indicted in U.S. crackdown

The U.S. indicted Russian Rustam Gallyamov for leading the Qakbot botnet, which infected 700K+ devices…

2 days ago

Operation RapTor led to the arrest of 270 dark web vendors and buyers

Law enforcement operation codenamed 'Operation RapTor' led to the arrest of 270 dark web vendors…

3 days ago