Citadel botnet disruption
Extended pass entry, last reviewed August 21, 2026
What was taken down?
Coordinated technical action against Citadel command infrastructure; FBI worked alongside a Microsoft-led civil process targeting a large number of individual botnet instances.
See what happenedWhat happened to the people?
No individual outcomes are recorded against this entry.
Group accounted for: Not applicable
Did it stay down?
Not established in the public record. No later activity is recorded against this entry.
See what happened afterwardFBI Cyber Division coordinated with Microsoft's separate civil legal action to disrupt more than a thousand Citadel botnets used for banking fraud.
- Date
- June 2013
- Target
- Citadel, botnet
- Activity
- Malware and botnets
- Operational lead
- FBI
- Partners
- Microsoft DCU[1]
- Microsoft Digital Crimes Unit , technical partner
- Jurisdiction
- Not established
- Outcome
- Coordinated technical action against Citadel command infrastructure; FBI worked alongside a Microsoft-led civil process targeting a large number of individual botnet instances.
- Status
- Completed
- Legal mechanism
- FBI criminal process combined with a parallel Microsoft civil action (E.D.N.Y./W.D.N.C. civil orders for the Microsoft side)
- Group accounted for
- Not applicable
Infrastructure
Domains seized, with no count in the record.
| Identifier | Recorded as | Status | Notes |
|---|---|---|---|
| Not published | Domain | Seized, United States | Domains/servers associated with over a thousand individual Citadel botnet instances.[1] |
Domains and onion addresses are shown defanged. Where the record gives a count but no identifier, the count is shown in place of one. This list carries only what appears in the cited sources.
No individual is named against this entry in the cited record. That is a gap in what has been published rather than a finding that nobody was involved.
Group accounted for: Not applicable
Framed publicly as an infrastructure-disruption operation rather than a personnel-capture operation.
Not established in the public record. No later activity is recorded against this entry.
Numbered markers throughout this entry link to the source that supports the claim beside them.
Official sources
-
[1]
Citadel botnet disruption announcement
Establishes FBI coordination with Microsoft's civil action against Citadel infrastructure.