Malware
PHOTOLITE
PHOTOLITE is the lite version of the GZIPLOADER with limited capabilities i.e.
PHOTOLITE is a Windows malware family.
Background
PHOTOLITE is a stripped-down edition of GZIPLOADER offering reduced functionality; for instance, it cannot exfiltrate host details. This variant appeared as a follow-on payload in a TA542 Emotet campaign in November '22. It carries a hardcoded URL to retrieve a "Bot Pack" file under the fixed name botpack.dat, yielding the IcedID Lite DLL Loader, which in turn deploys the Forked version of the IcedID Bot without the webinjects and backconnect features ordinarily used for banking fraud.
Source: Malpedia (Fraunhofer FKIE).