<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>Naked Security &#187; citadel</title>
	<atom:link href="http://nakedsecurity.sophos.com/tag/citadel/feed/" rel="self" type="application/rss+xml" />
	<link>http://nakedsecurity.sophos.com</link>
	<description>Computer Security · News · Opinion · Advice · Research</description>
	<lastBuildDate>Sun, 19 May 2013 03:21:35 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
<cloud domain='nakedsecurity.sophos.com' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://s2.wp.com/i/buttonw-com.png</url>
		<title>Naked Security &#187; citadel</title>
		<link>http://nakedsecurity.sophos.com</link>
	</image>
	<atom:link rel="search" type="application/opensearchdescription+xml" href="http://nakedsecurity.sophos.com/osd.xml" title="Naked Security" />
	<atom:link rel='hub' href='http://nakedsecurity.sophos.com/?pushpress=hub'/>
		<item>
		<title>NBC website hacked and distributes malware - here&#039;s what happened</title>
		<link>http://nakedsecurity.sophos.com/2013/02/22/nbc-website-hacked-and-distributes-malware/?utm_source=Naked%2520Security%2520-%2520Feed&#038;utm_medium=feed&#038;utm_content=rss2&#038;utm_campaign=Feed</link>
		<comments>http://nakedsecurity.sophos.com/2013/02/22/nbc-website-hacked-and-distributes-malware/?utm_source=Naked%2520Security%2520-%2520Feed&#038;utm_medium=feed&#038;utm_content=rss2&#038;utm_campaign=Feed#comments</comments>
		<pubDate>Fri, 22 Feb 2013 08:48:09 +0000</pubDate>
		<dc:creator>Paul Ducklin</dc:creator>
				<category><![CDATA[Featured]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Vulnerability]]></category>
		<category><![CDATA[citadel]]></category>
		<category><![CDATA[Exploit]]></category>
		<category><![CDATA[Exploit Kit]]></category>
		<category><![CDATA[hack]]></category>
		<category><![CDATA[NBC]]></category>
		<category><![CDATA[redirect]]></category>
		<category><![CDATA[ZeroAccess]]></category>

		<guid isPermaLink="false">http://nakedsecurity.sophos.com/?p=217607</guid>
		<description><![CDATA[The latest high-profile organisation to fall victim to cybercriminals is the US television network NBC.

NBC's website was "owned" and used as a go-between in a campaign to infect online visitors automatically.<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=nakedsecurity.sophos.com&#038;blog=15254721&#038;post=217607&#038;subd=sophosnews&#038;ref=&#038;feed=1" width="1" height="1" />]]></description>
		<wfw:commentRss>http://nakedsecurity.sophos.com/2013/02/22/nbc-website-hacked-and-distributes-malware/?utm_source=Naked%2520Security%2520-%2520Feed&#038;utm_medium=feed&#038;utm_content=rss2&#038;utm_campaign=Feed/feed/</wfw:commentRss>
		<slash:comments>11</slash:comments>
	
		<media:thumbnail url="http://sophosnews.files.wordpress.com/2013/02/nbc-tower-250.png?w=150" />
		<media:content url="http://sophosnews.files.wordpress.com/2013/02/nbc-tower-250.png?w=150" medium="image">
			<media:title type="html">nbc-tower-250</media:title>
		</media:content>

		<media:content url="http://0.gravatar.com/avatar/025c4bb891cbc5a1bb24a4854f823e48?s=96&#38;d=http%3A%2F%2F0.gravatar.com%2Favatar%2Fad516503a11cd5ca435acc9bb6523536%3Fs%3D96&#38;r=G" medium="image">
			<media:title type="html">pducklin</media:title>
		</media:content>

		<media:content url="http://sophosnews.files.wordpress.com/2013/02/nbc-tower-176.png" medium="image" />
	</item>
		<item>
		<title>Point of sale devices and Canadian banks targeted by Citadel malware variant</title>
		<link>http://nakedsecurity.sophos.com/2013/01/28/citadel-point-of-sale-banks/?utm_source=Naked%2520Security%2520-%2520Feed&#038;utm_medium=feed&#038;utm_content=rss2&#038;utm_campaign=Feed</link>
		<comments>http://nakedsecurity.sophos.com/2013/01/28/citadel-point-of-sale-banks/?utm_source=Naked%2520Security%2520-%2520Feed&#038;utm_medium=feed&#038;utm_content=rss2&#038;utm_campaign=Feed#comments</comments>
		<pubDate>Mon, 28 Jan 2013 17:12:06 +0000</pubDate>
		<dc:creator>James Wyke</dc:creator>
				<category><![CDATA[Botnet]]></category>
		<category><![CDATA[Featured]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Security threats]]></category>
		<category><![CDATA[SophosLabs]]></category>
		<category><![CDATA[citadel]]></category>
		<category><![CDATA[crimeware]]></category>
		<category><![CDATA[crimeware kit]]></category>
		<category><![CDATA[point of sale]]></category>
		<category><![CDATA[POS]]></category>
		<category><![CDATA[Zbot]]></category>
		<category><![CDATA[Zeus]]></category>

		<guid isPermaLink="false">http://nakedsecurity.sophos.com/?p=205893</guid>
		<description><![CDATA[A new variant of the prevalent Citadel crimeware kit has been discovered to target Point of Sale (POS) devices.  Find out more, in this analysis from SophosLabs expert James Wyke.<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=nakedsecurity.sophos.com&#038;blog=15254721&#038;post=205893&#038;subd=sophosnews&#038;ref=&#038;feed=1" width="1" height="1" />]]></description>
		<wfw:commentRss>http://nakedsecurity.sophos.com/2013/01/28/citadel-point-of-sale-banks/?utm_source=Naked%2520Security%2520-%2520Feed&#038;utm_medium=feed&#038;utm_content=rss2&#038;utm_campaign=Feed/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
	
		<media:thumbnail url="http://sophosnews.files.wordpress.com/2013/01/pos-thumb.jpg?w=150" />
		<media:content url="http://sophosnews.files.wordpress.com/2013/01/pos-thumb.jpg?w=150" medium="image">
			<media:title type="html">Point of sale devices and Canadian banks targeted by Citadel malware variant</media:title>
		</media:content>

		<media:content url="http://0.gravatar.com/avatar/326e90fc62c299f2180bdb5139866796?s=96&#38;d=http%3A%2F%2F0.gravatar.com%2Favatar%2Fad516503a11cd5ca435acc9bb6523536%3Fs%3D96&#38;r=G" medium="image">
			<media:title type="html">jameswyke</media:title>
		</media:content>

		<media:content url="http://sophosnews.files.wordpress.com/2013/01/citadel-170.jpg" medium="image">
			<media:title type="html">Citadel. Image from Shutterstock</media:title>
		</media:content>

		<media:content url="http://sophosnews.files.wordpress.com/2013/01/pos-170.jpg" medium="image">
			<media:title type="html">Point of sales device. Image from Shutterstock</media:title>
		</media:content>

		<media:content url="http://sophosnews.files.wordpress.com/2013/01/screen-capture.jpg" medium="image">
			<media:title type="html">Screen capture</media:title>
		</media:content>

		<media:content url="http://sophosnews.files.wordpress.com/2013/01/image3.jpg" medium="image">
			<media:title type="html">image3</media:title>
		</media:content>

		<media:content url="http://sophosnews.files.wordpress.com/2013/01/processes.jpg" medium="image">
			<media:title type="html">List of processes</media:title>
		</media:content>
	</item>
		<item>
		<title>Monday review - the hot 22 stories of the week</title>
		<link>http://nakedsecurity.sophos.com/2012/12/10/monday-review-the-hot-22-stories-of-the-week-2/?utm_source=Naked%2520Security%2520-%2520Feed&#038;utm_medium=feed&#038;utm_content=rss2&#038;utm_campaign=Feed</link>
		<comments>http://nakedsecurity.sophos.com/2012/12/10/monday-review-the-hot-22-stories-of-the-week-2/?utm_source=Naked%2520Security%2520-%2520Feed&#038;utm_medium=feed&#038;utm_content=rss2&#038;utm_campaign=Feed#comments</comments>
		<pubDate>Mon, 10 Dec 2012 00:01:15 +0000</pubDate>
		<dc:creator>Anna Brading</dc:creator>
				<category><![CDATA[Android]]></category>
		<category><![CDATA[Facebook]]></category>
		<category><![CDATA[Featured]]></category>
		<category><![CDATA[Google]]></category>
		<category><![CDATA[Law & order]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[Privacy]]></category>
		<category><![CDATA[Security threats]]></category>
		<category><![CDATA[Social networks]]></category>
		<category><![CDATA[SophosLabs]]></category>
		<category><![CDATA[citadel]]></category>
		<category><![CDATA[Deepnet]]></category>
		<category><![CDATA[Dockster]]></category>
		<category><![CDATA[EU]]></category>
		<category><![CDATA[Instagram]]></category>
		<category><![CDATA[John McAfee]]></category>
		<category><![CDATA[OS X]]></category>
		<category><![CDATA[PayPal]]></category>
		<category><![CDATA[sha-1]]></category>
		<category><![CDATA[Threat Report]]></category>
		<category><![CDATA[Tor]]></category>
		<category><![CDATA[Tumblr]]></category>
		<category><![CDATA[tumblr worm]]></category>

		<guid isPermaLink="false">http://nakedsecurity.sophos.com/?p=208107</guid>
		<description><![CDATA[Here you go. 

All the stories we wrote in the past seven days, in case you missed anything (or just want to read them again).<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=nakedsecurity.sophos.com&#038;blog=15254721&#038;post=208107&#038;subd=sophosnews&#038;ref=&#038;feed=1" width="1" height="1" />]]></description>
		<wfw:commentRss>http://nakedsecurity.sophos.com/2012/12/10/monday-review-the-hot-22-stories-of-the-week-2/?utm_source=Naked%2520Security%2520-%2520Feed&#038;utm_medium=feed&#038;utm_content=rss2&#038;utm_campaign=Feed/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:thumbnail url="http://sophosnews.files.wordpress.com/2012/12/dow-250.png?w=150" />
		<media:content url="http://sophosnews.files.wordpress.com/2012/12/dow-250.png?w=150" medium="image" />

		<media:content url="http://2.gravatar.com/avatar/b2c72340090fc126218d98955474943b?s=96&#38;d=http%3A%2F%2F2.gravatar.com%2Favatar%2Fad516503a11cd5ca435acc9bb6523536%3Fs%3D96&#38;r=G" medium="image">
			<media:title type="html">annabrading</media:title>
		</media:content>
	</item>
		<item>
		<title>The Citadel crimeware kit - under the microscope</title>
		<link>http://nakedsecurity.sophos.com/2012/12/05/the-citadel-crimeware-kit-under-the-microscope/?utm_source=Naked%2520Security%2520-%2520Feed&#038;utm_medium=feed&#038;utm_content=rss2&#038;utm_campaign=Feed</link>
		<comments>http://nakedsecurity.sophos.com/2012/12/05/the-citadel-crimeware-kit-under-the-microscope/?utm_source=Naked%2520Security%2520-%2520Feed&#038;utm_medium=feed&#038;utm_content=rss2&#038;utm_campaign=Feed#comments</comments>
		<pubDate>Wed, 05 Dec 2012 07:41:22 +0000</pubDate>
		<dc:creator>James Wyke</dc:creator>
				<category><![CDATA[Botnet]]></category>
		<category><![CDATA[Featured]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Security threats]]></category>
		<category><![CDATA[SophosLabs]]></category>
		<category><![CDATA[citadel]]></category>
		<category><![CDATA[crimeware]]></category>
		<category><![CDATA[Zbot]]></category>
		<category><![CDATA[Zeus]]></category>

		<guid isPermaLink="false">http://nakedsecurity.sophos.com/?p=207335</guid>
		<description><![CDATA[Ever since the source code of Zeus/Zbot leaked in May 2011, many new variants have appeared.

One particularly prevalent example is <em>Citadel</em>. 

James Wyke of SophosLabs puts it under the microscope....<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=nakedsecurity.sophos.com&#038;blog=15254721&#038;post=207335&#038;subd=sophosnews&#038;ref=&#038;feed=1" width="1" height="1" />]]></description>
		<wfw:commentRss>http://nakedsecurity.sophos.com/2012/12/05/the-citadel-crimeware-kit-under-the-microscope/?utm_source=Naked%2520Security%2520-%2520Feed&#038;utm_medium=feed&#038;utm_content=rss2&#038;utm_campaign=Feed/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
	
		<media:thumbnail url="http://sophosnews.files.wordpress.com/2012/12/citadel-logo-250.png?w=150" />
		<media:content url="http://sophosnews.files.wordpress.com/2012/12/citadel-logo-250.png?w=150" medium="image">
			<media:title type="html">The Citadel crimeware kit - under the microscope</media:title>
		</media:content>

		<media:content url="http://0.gravatar.com/avatar/326e90fc62c299f2180bdb5139866796?s=96&#38;d=http%3A%2F%2F0.gravatar.com%2Favatar%2Fad516503a11cd5ca435acc9bb6523536%3Fs%3D96&#38;r=G" medium="image">
			<media:title type="html">jameswyke</media:title>
		</media:content>

		<media:content url="http://sophosnews.files.wordpress.com/2012/12/citadel-fig-01.png" medium="image" />

		<media:content url="http://sophosnews.files.wordpress.com/2012/12/citadel-fig-021.png" medium="image" />

		<media:content url="http://sophosnews.files.wordpress.com/2012/12/citadel-fig-031.png" medium="image" />

		<media:content url="http://sophosnews.files.wordpress.com/2012/12/citadel-fig-04.png" medium="image">
			<media:title type="html">POST request procedure to fetch configuration</media:title>
		</media:content>

		<media:content url="http://sophosnews.files.wordpress.com/2012/12/citadel-fig-05.png" medium="image" />

		<media:content url="http://sophosnews.files.wordpress.com/2012/12/citadel-fig-06.png" medium="image" />

		<media:content url="http://sophosnews.files.wordpress.com/2012/12/citadel-fig-07.png" medium="image" />

		<media:content url="http://sophosnews.files.wordpress.com/2012/12/citadel-fig-08.png" medium="image" />

		<media:content url="http://sophosnews.files.wordpress.com/2012/12/citadel-fig-09.png" medium="image" />

		<media:content url="http://sophosnews.files.wordpress.com/2012/12/citadel-fig-10.png" medium="image">
			<media:title type="html">citadel-fig-10</media:title>
		</media:content>

		<media:content url="http://sophosnews.files.wordpress.com/2012/12/citadel-fig-11.png" medium="image">
			<media:title type="html">citadel-fig-11</media:title>
		</media:content>
	</item>
		<item>
		<title>Reveton/FBI ransomware - exposed, explained and eliminated [VIDEO]</title>
		<link>http://nakedsecurity.sophos.com/2012/08/29/reveton-ransomware-exposed-explained-and-eliminated/?utm_source=Naked%2520Security%2520-%2520Feed&#038;utm_medium=feed&#038;utm_content=rss2&#038;utm_campaign=Feed</link>
		<comments>http://nakedsecurity.sophos.com/2012/08/29/reveton-ransomware-exposed-explained-and-eliminated/?utm_source=Naked%2520Security%2520-%2520Feed&#038;utm_medium=feed&#038;utm_content=rss2&#038;utm_campaign=Feed#comments</comments>
		<pubDate>Wed, 29 Aug 2012 15:40:25 +0000</pubDate>
		<dc:creator>Paul Ducklin</dc:creator>
				<category><![CDATA[Featured]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Video]]></category>
		<category><![CDATA[blackmail]]></category>
		<category><![CDATA[citadel]]></category>
		<category><![CDATA[cleanup]]></category>
		<category><![CDATA[Cybercrime]]></category>
		<category><![CDATA[extortion]]></category>
		<category><![CDATA[FBI]]></category>
		<category><![CDATA[ransom]]></category>
		<category><![CDATA[reveton]]></category>
		<category><![CDATA[standover]]></category>
		<category><![CDATA[troj/ransom]]></category>

		<guid isPermaLink="false">http://nakedsecurity.sophos.com/?p=183559</guid>
		<description><![CDATA[Many of you have been asking us about the Reveton ransomware, which claims that the FBI has fined you, and locks you out of your PC until you pay up.

Learn what it looks like, and what to do if you or one of your friends and family encounter it...<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=nakedsecurity.sophos.com&#038;blog=15254721&#038;post=183559&#038;subd=sophosnews&#038;ref=&#038;feed=1" width="1" height="1" />]]></description>
		<wfw:commentRss>http://nakedsecurity.sophos.com/2012/08/29/reveton-ransomware-exposed-explained-and-eliminated/?utm_source=Naked%2520Security%2520-%2520Feed&#038;utm_medium=feed&#038;utm_content=rss2&#038;utm_campaign=Feed/feed/</wfw:commentRss>
		<slash:comments>25</slash:comments>
	
		<media:thumbnail url="http://sophosnews.files.wordpress.com/2012/08/reveton-ransomware-video-250.png?w=150" />
		<media:content url="http://sophosnews.files.wordpress.com/2012/08/reveton-ransomware-video-250.png?w=150" medium="image">
			<media:title type="html">Reveton ransomware - exposed, explained and eliminated</media:title>
		</media:content>

		<media:content url="http://0.gravatar.com/avatar/025c4bb891cbc5a1bb24a4854f823e48?s=96&#38;d=http%3A%2F%2F0.gravatar.com%2Favatar%2Fad516503a11cd5ca435acc9bb6523536%3Fs%3D96&#38;r=G" medium="image">
			<media:title type="html">pducklin</media:title>
		</media:content>
	</item>
	</channel>
</rss>
