Threat Group Cards: A Threat Actor Encyclopedia Archived: 2026-04-05 12:34:50 UTC Home > List all groups > List all tools > List all groups using tool ZeroT Tool: ZeroT Names ZeroT Category Malware Type Downloader Description (Proofpoint) Since the summer of 2016, this group began using a new downloader known as ZeroT to install the PlugX remote access Trojan (RAT) and added Microsoft Compiled HTML Help (.chm) as one of the initial droppers delivered in spear-phishing emails. Information MITRE ATT&CK Malpedia Last change to this tool card: 23 April 2020 Download this tool card in JSON format All groups using tool ZeroT Changed Name Country Observed APT groups TA459 2017-Apr 2022 1 group listed (1 APT, 0 other, 0 unknown) Source: https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=5cf6ff0f-654a-4a92-8ea7-35f4ebbc0068 https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=5cf6ff0f-654a-4a92-8ea7-35f4ebbc0068 Page 1 of 1