Malware
Derusbi
aka PHOTO
A DLL backdoor also reported publicly as “Derusbi”, capable of obtaining directory, file, and drive listing; creating a reverse shell; performing screen captures; recording video and audio; listing, t
Derusbi, also known as PHOTO, is a Windows malware family operated by APT41, APT17 and others.
Background
Publicly known as “Derusbi”, this DLL backdoor offers a broad feature set: it can enumerate directories, files, and drives; open a reverse shell; capture the screen; record video and audio; list, kill, and spawn processes; enumerate, create, and remove registry keys and values; log keystrokes; recover usernames and passwords from protected storage; and rename, delete, copy, move, read, and write files.
Source: Malpedia (Fraunhofer FKIE).