The actual threat actors using the client are likely low-to-mid level cybercriminals who use the stolen data for:

Manual removal has a high risk of missing a file. Security vendors have updated their definitions to detect Tarasande.

Warning: Manual removal is risky. If you suspect infection, disconnect from the internet immediately.