Skip to main content
Back to the takedown index

Citadel botnet disruption

June 2013, Malware and botnets
Led by Federal Bureau of Investigation

Extended pass entry, last reviewed August 21, 2026

What was taken down?

Coordinated technical action against Citadel command infrastructure; FBI worked alongside a Microsoft-led civil process targeting a large number of individual botnet instances.

See what happened

What happened to the people?

No individual outcomes are recorded against this entry.
Group accounted for: Not applicable

See people and accountability

Did it stay down?

Not established in the public record. No later activity is recorded against this entry.

See what happened afterward

FBI Cyber Division coordinated with Microsoft's separate civil legal action to disrupt more than a thousand Citadel botnets used for banking fraud.

Date
June 2013
Target
Citadel, botnet
Activity
Malware and botnets
Operational lead
FBI
Partners
Microsoft DCU[1]
Jurisdiction
Not established
Outcome
Coordinated technical action against Citadel command infrastructure; FBI worked alongside a Microsoft-led civil process targeting a large number of individual botnet instances.
Status
Completed
Legal mechanism
FBI criminal process combined with a parallel Microsoft civil action (E.D.N.Y./W.D.N.C. civil orders for the Microsoft side)
Group accounted for
Not applicable

Infrastructure

Domains seized, with no count in the record.

Identifier Recorded as Status Notes
Not published Domain Seized, United States Domains/servers associated with over a thousand individual Citadel botnet instances.[1]

Domains and onion addresses are shown defanged. Where the record gives a count but no identifier, the count is shown in place of one. This list carries only what appears in the cited sources.

No individual is named against this entry in the cited record. That is a gap in what has been published rather than a finding that nobody was involved.

Group accounted for: Not applicable

Framed publicly as an infrastructure-disruption operation rather than a personnel-capture operation.

See the organizations and roles behind this action

Not established in the public record. No later activity is recorded against this entry.

Numbered markers throughout this entry link to the source that supports the claim beside them.

Official sources

  1. [1]
    Citadel botnet disruption announcement

    FBI Cyber Division, June 5, 2013, Source grade S2

    Establishes FBI coordination with Microsoft's civil action against Citadel infrastructure.

    No address recorded for this source. Publisher, title, and date are given so it can be retrieved from the publisher.

Coverage note. Added from deep-research aggregation pass. Not independently re-verified source-by-source to the same standard as the original 38-incident core; source_quality capped at S2/P2 pending a dedicated verification pass.