Emissary Panda, which also goes by other identikits such as APT27, IronTiger, BronzeUnion, TG-3390, and LuckyMouse , is a decade old Chinese APT. It primarily targets aerospace, government, defense, technology, energy, and manufacturing sectors. Not much is know about the activities of this group.
InnfiRAT remote access Trojan is written in .net. It primarily steals his victim's information such as browser cookies, crypto currency wallet details, session data.
TFlower Ransomware is being installed in a corporate network through exposed Remote Desktop services that are being hacked by attackers.
FrameworkPOS, aka TRINITY, is POS malware associated with a threat actor FIN6. It is designed to capture physical point-of-sales systems in order to gain Track1 and Track2 data, which includes credit card account number, expiration date, and more.
JSWorm as the name might have suggest that perhaps it is a Worm written in JavaScript, is not true. It is a ransomware which encrypts its victims file and ask for BTC to decrypt them back.