Threat reportMalwareTL-2026-1592
NULLZEREPTOOL: Telegram-Controlled Python DDoS and Multi-Function Attack Framework
NULLZEREPTOOL (TL-2026-1592), also tracked as NULLZEREPTOOL, is a medium-severity malware campaign, first published 2026-07-21. It has no confirmed attribution, maps to 18 MITRE ATT&CK techniques (T1005, T1016, T1041), and is covered by 9 detection rules and 29 indicators of compromise.
- Severity
- MEDIUMAssessed severity
- CVEs
- 0None referenced
- Techniques
- 18MITRE ATT&CK
- Actors
- 0Not attributed
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 29Indicators of compromise
Key facts for TL-2026-1592
- Threat ID
- TL-2026-1592
- Also known as
- NULLZEREPTOOL
- Severity
- MEDIUM
- Status
- ACTIVE
- Category
- MALWARE
- First published
- Last reviewed
- Attribution confidence
- LOW
- Motivation
- FINANCIAL
- Target sectors
- ecommerce, news - media, gaming, finance
- Target regions
- Global, Southeast Asia, North America
- Detection rules
- 9
- Indicators of compromise
- 29
Malware and tooling in NULLZEREPTOOL
Malware and tooling: NULLZEREPTOOL, aireplay-ng, hashcat, hcxdumptool, telebot
How NULLZEREPTOOL works
NULLZEREPTOOL is a Python-based, Telegram-controlled DDoS-as-a-Service framework surfaced through two Pastebin source-code leaks (April 27 and April 29, 2026). It ships a 20-method Layer 3/4/7 DDoS engine with auto-scaling and proxy rotation behind a hardcoded Telegram bot C2 and single-use license-key access model; the later variant adds unconfirmed server-side wireless-attack, credential-extraction, and botnet-tasking modules.
NULLZEREPTOOL is a commodity DDoS-as-a-Service (DDoSaaS) tool written in Python and controlled entirely through a Telegram bot (via the `telebot` library), discovered by Flare's dark-web/paste-site monitoring across two separate Pastebin uploads two days apart (Rxk4VgnX on 2026-04-27, ryxQ077S on 2026-04-29). The core is a 20-method attack engine dispatched from a METHODS dictionary, including combo_worker (interleaved HTTP/UDP/TCP), http_worker, udp_worker, tcp_worker, slowloris_worker, dns_amplification_worker (50x repeated queries reflected off 8.8.8.8 and 1.1.1.1), and ntp_amplification_worker (monlist requests reflected off time.google.com and pool.ntp.org). An auto-scaling controller checks observed RPS every 15 seconds and grows the worker pool (current x 1.2 + 10, capped at 2,000 threads, up to 1,000 initial threads with 1ms minimum per-worker delay) whenever throughput falls below 70% of the operator-set target. A seven-source proxy harvesting/validation pipeline (api.proxyscrape.com, proxylist.geonode.com, free-proxy-list.net, and four unnamed GitHub raw-file sources) validates candidates against httpbin.org/ip with a 5-second timeout, retaining only sub-2-second responders, and supports live rotation via the /proxy Telegram command.
Operator access is gated by a SQLite-backed (c2.db) single-use license-key system: keys are generated with secrets.token_hex(10) into 20-character hex strings, default max-uses of 1, with admin commands /key [days], /keys, and /delkey — consistent with a tiered-access or resale/reseller distribution model typical of low-tier booter/stresser markets. The Telegram bot itself is gated by a hardcoded operator Telegram ID (7593738229) and a fixed plaintext password ("7788") accepted by the /login command, tracked in a logged_in session dictionary; /attacks, /proxy, /key, /cvv, /stats round out the command surface, with periodic in-chat stats messages during active floods.
Observed live attack sessions recovered from the leaked artifacts show operational use against shopmuabancf[.]com (an e-commerce site, 20,000 RPS combo attack, 10,404 requests, successful), Bloomberg.com (200,000 RPS combo attack, watchdog declared the target dead with 0 completed requests logged), and Trangchubloxfruit[.]com (a Roblox/gaming-adjacent site, 50,000 RPS combo attack, only 132 requests — low throughput). Vietnamese-language comments and bot response strings throughout the source point to a Vietnamese-speaking developer/operator community; overall sophistication is assessed as low, consistent with widespread booter/stresser tooling rather than an advanced or state-linked capability.
The later (April 29) variant adds three server-side modules whose end-to-end functionality Flare could not confirm because the corresponding client binary (client.py) was absent from the leaked artifacts: (1) a wireless-attack module wrapping aireplay-ng and netsh wlan disconnect for WiFi deauthentication, l2ping -f / hcitool dc for Bluetooth disruption (Linux-only, requires root), netsh wlan show profiles key=clear / nmcli for saved WiFi credential extraction, and a three-stage hcxdumptool -> hcxpcapngtool -> hashcat WiFi-cracking workflow; (2) a credential/financial-data module exposing manual /cvv <cc> <cvv> <exp> entry into a cvv_logs table (cc, cvv, exp, time) retrievable via /getcvv, a /wifipass command for extracted WiFi profiles, and a referenced but unimplemented "browser_steal" task type with no corresponding parsing code; and (3) a Flask-based botnet-tasking layer exposing /slave_register, /slave_get_task, and /slave_report endpoints, a BOTNET_HIERARCHY structure tracking masters/slaves/task queues/completions, task types wifi_scan, browser_steal, and full_steal, and Telegram commands /botnet_task, /botnetdata, /botnetslaves, /botnetexport. Flare assessed this later feature set as still in a feature-testing phase given the missing client component.
No CVE or software vulnerability underlies this threat — it is a commodity attack tool/campaign. Its practical risk is availability impact from Layer 3/4/7 DDoS at meaningful scale (validated against a Bloomberg-class target), a low barrier to entry via public Pastebin distribution and license-key resale, and an emerging trajectory toward broader botnet C2 and credential-theft capability that defenders should track even while unconfirmed.
MITRE ATT&CK techniques used in TL-2026-1592
Collection
T1005 Data from Local System; T1119 Automated Collection
Discovery
T1016 System Network Configuration Discovery; T1518 Software Discovery
Exfiltration
T1041 Exfiltration Over C2 Channel
Execution
T1059 Command and Scripting Interpreter
Command and Control
T1071 Application Layer Protocol; T1102 Web Service
command-and-control
Impact
T1498 Network Denial of Service; T1499 Endpoint Denial of Service
Credential Access
T1552 Unsecured Credentials; T1555 Credentials from Password Stores; T1557 Adversary-in-the-Middle
Resource Development
T1583 Acquire Infrastructure; T1585 Establish Accounts; T1588 Obtain Capabilities
Reconnaissance
Remediation for NULLZEREPTOOL
Immediate actions
- Deploy or verify upstream DDoS scrubbing / CDN-based mitigation (rate limiting, WAF challenge pages) for internet-facing web properties
- Block or rate-limit inbound UDP responses from open DNS resolvers (8.8.8.8, 1.1.1.1) and NTP servers (pool.ntp.org, time.google.com) at perimeter where reflection abuse is suspected
- Alert on abnormal outbound connections to api.telegram.org from unexpected hosts/processes as a potential bot-C2 indicator
- Monitor egress to known free-proxy aggregator domains (api.proxyscrape.com, proxylist.geonode.com, free-proxy-list.net) from server/workstation subnets
- Disable or tightly restrict OS-level WiFi credential export commands (netsh wlan show profiles key=clear, nmcli) via endpoint policy on hosts that do not require them
Workarounds
- Where DDoS scrubbing is unavailable, pre-stage IP allow-listing / geofencing for critical services known to be targeted (e-commerce, media, gaming)
- Rotate and monitor any exposed CVV/payment-capture forms for signs of manual data exfiltration consistent with the tool's /cvv workflow
Longer-term hardening
- Enforce BCP38/BCP84 (source-address validation) and disable open recursive DNS/NTP monlist responses on owned infrastructure to reduce amplification abuse
- Deploy network behavior analytics/EDR rules for slowloris-style partial-header connection holding and combo-style multi-protocol flood signatures
- Track Pastebin/paste-site and Telegram-channel leak monitoring feeds for reappearance of NULLZEREPTOOL variants or forks
- Harden WiFi deployments (WPA3, 802.11w management-frame protection) against deauthentication-based disruption
- Extend threat-hunting playbooks to cover Flask-based slave/botnet registration endpoints if internal hosts are suspected of running the later variant's server component
Timeline of NULLZEREPTOOL
- Earlier NULLZEREPTOOL variant uploaded to Pastebin under paste ID Rxk4VgnX, discovered by Flare via banner/keyword search of monitored paste sites.
- Analysis of the leaked c2.db and bot command surface (/key, /keys, /delkey) reveals a SQLite-backed single-use license-key system generated via secrets.token_hex(10), indicating a tiered-access or reseller distribution model typical of low-tier booter/stresser markets.
- Flare identifies three new server-side modules (wireless-attack, credential/CVV harvesting, Flask botnet-tasking layer) added in the later variant, but assesses them as an unconfirmed, still-in-testing feature set because the corresponding client.py binary is absent from the leaked artifacts.
- Recovered operator logs show a 50,000 RPS combo-method DDoS session against gaming-adjacent site trangchubloxfruit.com, yielding only 132 requests (low throughput).
- Recovered operator logs show a 200,000 RPS combo-method DDoS session targeting Bloomberg.com; the tool's own watchdog declared the target dead with 0 completed requests recorded.
- Recovered operator logs show a 20,000 RPS combo-method DDoS session against e-commerce site shopmuabancf.com, reaching 10,404 requests and assessed successful.
- Flare analysts confirm and begin technical analysis of the leaked NULLZEREPTOOL source across both variants.
- Later, more complete NULLZEREPTOOL variant (paste ID ryxQ077S) posted to Pastebin, flagged by Flare's automated source-code leak monitoring.
- Flare publishes public technical analysis of NULLZEREPTOOL, disclosing the DDoS engine, C2 mechanics, license-key model, and later variant's unconfirmed wireless/credential/botnet modules.
Sources cited for NULLZEREPTOOL
Detection coverage for TL-2026-1592
As of 2026-07-21, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1592 across Splunk SPL, Microsoft KQL and Sigma, covering 29 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.