Cert-Lexsi is a full member of FIRST since the beginning of this year. We had the opportunity to assist and speak at this organization’s annual conference in Malta last week with my colleague Jean-Michel: As usually in such conferences, I […]

Sorry, Mario, but the princess is in another citadel…

During the audit of an infected host looking for banking malware, we met a Citadel sample, identified by the folders it was stored in: “random” directory names in “C:\Documents and Settings\User\Application Data”, containing the binary, the modules or the configuration […]

Citadel: configuration file

We recently focused on the latest banking malware: Citadel. The Zeus source code release has made possible the creation of new banking malware, and Citadel is one of them. One of its particularities is the possibility for the customers to […]