Threat Group Cards: A Threat Actor Encyclopedia Archived: 2026-04-05 15:11:17 UTC Home > List all groups > List all tools > List all groups using tool Zingdoor Tool: Zingdoor Names Zingdoor Category Malware Type Backdoor Description (Trend Micro) Zingdoor is a new HTTP backdoor written in Go. While we first encountered Zingdoor in April 2023, some logs indicate that the earliest developments of this backdoor took place in June 2022. However, it had rarely been seen in the wild and had only been observed being used in a limited number of victims, likely as a newly designed backdoor with cross-platform capabilities. Zingdoor is packed using UPX and heavily obfuscated by a custom obfuscator engine. Information Last change to this tool card: 26 December 2024 Download this tool card in JSON format All groups using tool Zingdoor Changed Name Country Observed APT groups   Salt Typhoon, GhostEmperor 2020-Feb 2025 1 group listed (1 APT, 0 other, 0 unknown) Source: https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=e67dd84e-f8cc-4d6e-8af0-e212c2c3cc38 https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=e67dd84e-f8cc-4d6e-8af0-e212c2c3cc38 Page 1 of 1