Malware
JFMBackdoor
According to PwC Threat Intelligence, JFMBackdoor is a Windows DLL backdoor written in C++ that uses the CppServer library for communication.
JFMBackdoor is a Windows malware family operated by Calypso.
Background
As reported by PwC Threat Intelligence, JFMBackdoor is a C++ Windows DLL backdoor that leverages the CppServer library for its communications. Deployed through DLL side-loading, it offers a broad feature set spanning remote shell access, file system manipulation, network proxying, screenshot capture, registry operations, and self-deletion. The backdoor depends on encrypted configuration files and can update its behavior dynamically through them. It handles actions such as launching shells and managing services by interacting with system processes generically, and it captures screenshots via GDI+.
Source: Malpedia (Fraunhofer FKIE).