{"id":1711,"date":"2015-09-10T08:28:31","date_gmt":"2015-09-10T00:28:31","guid":{"rendered":"http:\/\/staging.bankvaultonline.com\/?p=1711"},"modified":"2015-09-10T08:28:31","modified_gmt":"2015-09-10T00:28:31","slug":"citadel-dridex-malware-hackers-arrested-europe","status":"publish","type":"post","link":"https:\/\/www.bankvault.com\/citadel-dridex-malware-hackers-arrested-europe\/","title":{"rendered":"Citadel and Dridex Malware Hackers Arrested in Europe"},"content":{"rendered":"

A Russian and a Moldovan were arrested in Europe with suspicion of being among the key masterminds behind the malicious Citadel and Dridex banking malware.<\/h2>\n

Authorities in Europe allege that the two suspects who were either staying together or traveling together were the ones behind the making as well as the deployment of this malware. Both suspects were arrested outside their native countries and are facing extradition to the U.S.<\/p>\n

In Paphos, a coastal tourist destination in Cyprus, a 30 year old man was arrested recently. The man who is from Moldova and wanted in the US was allegedly staying with his wife at the time of the arrest. Apart from the fact that the authorities believe that the man was responsible for bank fraud of more than $3.5M using his PC, there were no other details available in the Cyprus Mail.<\/p>\n

The man is also alleged to be an important player in the development of the sophisticated malicious bank malware called Dridex. This malware is also known as \u2018Cridex, Bugat’. According to a reliable source inside the investigating team, the crime gang that this man belonged has so far managed to steal over $100 million worldwide. This Dridex gang is thought to have evolved from the Eastern Europe cybercrime gang \u2018Business Club\u2019.<\/p>\n

The Gameover Zeus Botnet was a complex and sophisticated cybercrime network that operated globally and which had affected more than 500,000 PCs before mid 2014. In June 2014 international law enforcement agencies which included the US Department of Justice started working together to bring down this Business Club\u2019s strategic asset. This malware had been used many times for cyberheists. In July 2014, just a month after the breaking up of The Gameover, Dridex started being seen.<\/p>\n

Meanwhile, Norwegian press reported that \u2018Mark\u2019, a Russian national was arrested in Fredrikstad, Norway. The 27 year old man was arrested on request from the FBI. According to the FBI, Mark is the man responsible for the development and deployment of Citadel. This malware is a service product that is thought to have been used in numerous cyberheists targeting European and American small businesses.<\/p>\n

According to authorities, it is believed that the Pennsylvania heating and air conditioning vendor whose clients\u2019 usernames and passwords were stolen was a target of Citadel. It is using these same stolen details that Citadel managed to breach and steal from over 40 million credit cards issued by Target Corp in late 2013.<\/p>\n","protected":false},"excerpt":{"rendered":"

A Russian and a Moldovan were arrested in Europe with suspicion of being among the key masterminds behind the malicious Citadel and Dridex banking malware. Authorities in Europe allege that the two suspects who were either staying together or traveling together were the ones behind the making as well as the deployment of this malware. […]<\/p>\n","protected":false},"author":2,"featured_media":5683,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[37],"tags":[145,128,142,62,146],"class_list":["post-1711","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-security-news","tag-banking-malware","tag-citadel-trojan","tag-dridex","tag-krebs","tag-krebs-on-security"],"yoast_head":"\nCitadel and Dridex Malware Hackers Arrested in Europe - BankVault<\/title>\n<meta name=\"description\" content=\"The citadel banking trojan and dridex malware were used in Europe to steal millions from banks. They have now been arrested. Here's how they did it.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.bankvault.com\/citadel-dridex-malware-hackers-arrested-europe\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Citadel and Dridex Malware Hackers Arrested in Europe - BankVault\" \/>\n<meta property=\"og:description\" content=\"The citadel banking trojan and dridex malware were used in Europe to steal millions from banks. They have now been arrested. Here's how they did it.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.bankvault.com\/citadel-dridex-malware-hackers-arrested-europe\/\" \/>\n<meta property=\"og:site_name\" content=\"BankVault\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/BankVaultOnline\/\" \/>\n<meta property=\"article:published_time\" content=\"2015-09-10T00:28:31+00:00\" \/>\n<meta name=\"author\" content=\"BankVault\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@bankvaultonline\" \/>\n<meta name=\"twitter:site\" content=\"@bankvaultonline\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"BankVault\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"2 minutes\" \/>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Citadel and Dridex Malware Hackers Arrested in Europe - BankVault","description":"The citadel banking trojan and dridex malware were used in Europe to steal millions from banks. They have now been arrested. Here's how they did it.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.bankvault.com\/citadel-dridex-malware-hackers-arrested-europe\/","og_locale":"en_US","og_type":"article","og_title":"Citadel and Dridex Malware Hackers Arrested in Europe - BankVault","og_description":"The citadel banking trojan and dridex malware were used in Europe to steal millions from banks. They have now been arrested. Here's how they did it.","og_url":"https:\/\/www.bankvault.com\/citadel-dridex-malware-hackers-arrested-europe\/","og_site_name":"BankVault","article_publisher":"https:\/\/www.facebook.com\/BankVaultOnline\/","article_published_time":"2015-09-10T00:28:31+00:00","author":"BankVault","twitter_card":"summary_large_image","twitter_creator":"@bankvaultonline","twitter_site":"@bankvaultonline","twitter_misc":{"Written by":"BankVault","Est. reading time":"2 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.bankvault.com\/citadel-dridex-malware-hackers-arrested-europe\/#article","isPartOf":{"@id":"https:\/\/www.bankvault.com\/citadel-dridex-malware-hackers-arrested-europe\/"},"author":{"name":"BankVault","@id":"https:\/\/www.bankvault.com\/#\/schema\/person\/76e0aa85d5ac5405b47c0760eb9ab639"},"headline":"Citadel and Dridex Malware Hackers Arrested in Europe","datePublished":"2015-09-10T00:28:31+00:00","dateModified":"2015-09-10T00:28:31+00:00","mainEntityOfPage":{"@id":"https:\/\/www.bankvault.com\/citadel-dridex-malware-hackers-arrested-europe\/"},"wordCount":407,"commentCount":0,"publisher":{"@id":"https:\/\/www.bankvault.com\/#organization"},"image":{"@id":"https:\/\/www.bankvault.com\/citadel-dridex-malware-hackers-arrested-europe\/#primaryimage"},"thumbnailUrl":"","keywords":["banking malware","citadel trojan","Dridex","Krebs","krebs on security"],"articleSection":["IT security news"],"inLanguage":"en-AU","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/www.bankvault.com\/citadel-dridex-malware-hackers-arrested-europe\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/www.bankvault.com\/citadel-dridex-malware-hackers-arrested-europe\/","url":"https:\/\/www.bankvault.com\/citadel-dridex-malware-hackers-arrested-europe\/","name":"Citadel and Dridex Malware Hackers Arrested in Europe - BankVault","isPartOf":{"@id":"https:\/\/www.bankvault.com\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.bankvault.com\/citadel-dridex-malware-hackers-arrested-europe\/#primaryimage"},"image":{"@id":"https:\/\/www.bankvault.com\/citadel-dridex-malware-hackers-arrested-europe\/#primaryimage"},"thumbnailUrl":"","datePublished":"2015-09-10T00:28:31+00:00","dateModified":"2015-09-10T00:28:31+00:00","description":"The citadel banking trojan and dridex malware were used in Europe to steal millions from banks. They have now been arrested. Here's how they did it.","breadcrumb":{"@id":"https:\/\/www.bankvault.com\/citadel-dridex-malware-hackers-arrested-europe\/#breadcrumb"},"inLanguage":"en-AU","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.bankvault.com\/citadel-dridex-malware-hackers-arrested-europe\/"]}]},{"@type":"ImageObject","inLanguage":"en-AU","@id":"https:\/\/www.bankvault.com\/citadel-dridex-malware-hackers-arrested-europe\/#primaryimage","url":"","contentUrl":""},{"@type":"BreadcrumbList","@id":"https:\/\/www.bankvault.com\/citadel-dridex-malware-hackers-arrested-europe\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.bankvault.com\/"},{"@type":"ListItem","position":2,"name":"Citadel and Dridex Malware Hackers Arrested in Europe"}]},{"@type":"WebSite","@id":"https:\/\/www.bankvault.com\/#website","url":"https:\/\/www.bankvault.com\/","name":"BankVault","description":"cybersecurity","publisher":{"@id":"https:\/\/www.bankvault.com\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.bankvault.com\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-AU"},{"@type":"Organization","@id":"https:\/\/www.bankvault.com\/#organization","name":"BankVault","url":"https:\/\/www.bankvault.com\/","logo":{"@type":"ImageObject","inLanguage":"en-AU","@id":"https:\/\/www.bankvault.com\/#\/schema\/logo\/image\/","url":"https:\/\/www.bankvault.com\/wp-content\/uploads\/2018\/11\/BankVault-Logo-Light.png","contentUrl":"https:\/\/www.bankvault.com\/wp-content\/uploads\/2018\/11\/BankVault-Logo-Light.png","width":1212,"height":275,"caption":"BankVault"},"image":{"@id":"https:\/\/www.bankvault.com\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/BankVaultOnline\/","https:\/\/x.com\/bankvaultonline"]},{"@type":"Person","@id":"https:\/\/www.bankvault.com\/#\/schema\/person\/76e0aa85d5ac5405b47c0760eb9ab639","name":"BankVault","image":{"@type":"ImageObject","inLanguage":"en-AU","@id":"https:\/\/www.bankvault.com\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/?s=96&d=mm&r=g","caption":"BankVault"},"url":"https:\/\/www.bankvault.com\/author\/bankvault\/"}]}},"_links":{"self":[{"href":"https:\/\/www.bankvault.com\/wp-json\/wp\/v2\/posts\/1711","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.bankvault.com\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.bankvault.com\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.bankvault.com\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.bankvault.com\/wp-json\/wp\/v2\/comments?post=1711"}],"version-history":[{"count":0,"href":"https:\/\/www.bankvault.com\/wp-json\/wp\/v2\/posts\/1711\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.bankvault.com\/wp-json\/"}],"wp:attachment":[{"href":"https:\/\/www.bankvault.com\/wp-json\/wp\/v2\/media?parent=1711"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.bankvault.com\/wp-json\/wp\/v2\/categories?post=1711"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.bankvault.com\/wp-json\/wp\/v2\/tags?post=1711"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}