ZingDoor is a Go-based HTTP backdoor used in China-linked cyberespionage operations. It has been associated most notably with Earth Estries, also known as Glowworm and FamousSparrow, and has also appeared in intrusions attributed to other China-nexus clusters, including UAT-8302. The malware has been observed in campaigns targeting government entities, telecommunications providers, technology organizations, and other strategically significant victims across multiple regions.
ZingDoor is designed for post-compromise remote access and operator control. Documented capabilities include collecting system information, enumerating services and files, transferring files, and executing arbitrary commands on compromised hosts. It has been deployed alongside other Chinese espionage tooling such as SNAPPYBEE, ShadowPad, and KrustyLoader, indicating its role within broader multi-stage intrusion sets focused on persistence, internal access, and follow-on operations.
A characteristic deployment method is DLL sideloading using legitimate Windows software to load the malicious payload. Reporting has described ZingDoor masquerading as a benign DLL and being launched through trusted executables, including Windows Defender-related binaries and other legitimate signed programs, to blend into normal activity and evade detection. Persistence has also been established through Windows service creation. The malware has been described as obfuscated and packed to hinder analysis.
ZingDoor has been observed after exploitation of internet-facing enterprise software vulnerabilities, including in campaigns exploiting Microsoft SharePoint ToolShell vulnerabilities in 2025. In those intrusions, operators used ZingDoor after successful server compromise as part of espionage-oriented activity that also involved credential theft, lateral movement, proxying, and stealthy long-term access. Communications have in some cases been routed through internal proxy infrastructure to reduce visibility.
Overall, ZingDoor is best understood as a Windows backdoor used by China-linked threat actors for persistent access and remote tasking in long-duration espionage campaigns.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Zingdoor, which was deployed on the networks of all three organizations, has in the past been associated with the Chinese group Glowworm (aka Earth Estries, FamousSparrow). | China-based attackers used the ToolShell vulnerability (CVE-2025-53770) to compromise a telecoms company in the Middle East shortly after the vulnerability was publicly revealed and patched in July 2025... ToolShell affects on-premise SharePoint servers and gives an attacker unauthenticated access to vulnerable servers, allowing them to remotely execute code and access all content and file systems.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Zingdoor, which was deployed on the networks of all three organizations, has in the past been associated with the Chinese group Glowworm (aka Earth Estries, FamousSparrow).
In one documented intrusion, the group also deployed SNAPPYBEE and ZingDoor together, a tactic independently highlighted by Trend Micro in 2024 reporting on similar China-linked activity.
Deed RAT (aka Snappybee), a successor of ShadowPad, and Zingdoor, both of which have been deployed by Earth Estries in late 2024.
13 distinct techniques documented for this family, organized by ATT&CK tactic.
“We found Earth Estries compromising existing accounts with administrative privileges after it successfully infected one of the organization’s internal servers.”
China-based attackers used the ToolShell vulnerability (CVE-2025-53770) to compromise a telecoms company in the Middle East shortly after the vulnerability was publicly revealed and patched in July 2025... In these attacks, the attackers used other vulnerabilities for initial access and exploited SQL servers and Apache HTTP servers running the Adobe ColdFusion software to deliver their malware.
“Through the Server Message Block (SMB) and WMI command line (WMIC), the threat actors propagated backdoors and hacking tools…”
“Zingdoor is packed using UPX and heavily obfuscated…” / “TrillClient… heavily obfuscated… for anti-analysis.”
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
10 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned only to note that SNAPPYBEE appeared in ZINGDOOR attack chains.
Backdoor used together with SNAPPYBEE in a documented intrusion tied to UAT-8302.
Backdoor malware deployed by Earth Estries.
A DLL-based malware family used by UAT-8302, often in conjunction with SNAPPYBEE/DeedRAT. It has also been observed following exploitation activity in 2025.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.