Threat reportMalwareTL-2026-1592

NULLZEREPTOOL: Telegram-Controlled Python DDoS and Multi-Function Attack Framework

mediumACTIVE

NULLZEREPTOOL (TL-2026-1592), also tracked as NULLZEREPTOOL, is a medium-severity malware campaign, first published 2026-07-21. It has no confirmed attribution, maps to 18 MITRE ATT&CK techniques (T1005, T1016, T1041), and is covered by 9 detection rules and 29 indicators of compromise.

Severity
MEDIUMAssessed severity
CVEs
0None referenced
Techniques
18MITRE ATT&CK
Actors
0Not attributed
Detection rules
9SPL · KQL · Sigma
IOCs
29Indicators of compromise

Key facts for TL-2026-1592

Threat ID
TL-2026-1592
Also known as
NULLZEREPTOOL
Severity
MEDIUM
Status
ACTIVE
Category
MALWARE
First published
Last reviewed
Attribution confidence
LOW
Motivation
FINANCIAL
Target sectors
ecommerce, news - media, gaming, finance
Target regions
Global, Southeast Asia, North America
Detection rules
9
Indicators of compromise
29

Malware and tooling in NULLZEREPTOOL

Malware and tooling: NULLZEREPTOOL, aireplay-ng, hashcat, hcxdumptool, telebot

How NULLZEREPTOOL works

NULLZEREPTOOL is a Python-based, Telegram-controlled DDoS-as-a-Service framework surfaced through two Pastebin source-code leaks (April 27 and April 29, 2026). It ships a 20-method Layer 3/4/7 DDoS engine with auto-scaling and proxy rotation behind a hardcoded Telegram bot C2 and single-use license-key access model; the later variant adds unconfirmed server-side wireless-attack, credential-extraction, and botnet-tasking modules.

NULLZEREPTOOL is a commodity DDoS-as-a-Service (DDoSaaS) tool written in Python and controlled entirely through a Telegram bot (via the `telebot` library), discovered by Flare's dark-web/paste-site monitoring across two separate Pastebin uploads two days apart (Rxk4VgnX on 2026-04-27, ryxQ077S on 2026-04-29). The core is a 20-method attack engine dispatched from a METHODS dictionary, including combo_worker (interleaved HTTP/UDP/TCP), http_worker, udp_worker, tcp_worker, slowloris_worker, dns_amplification_worker (50x repeated queries reflected off 8.8.8.8 and 1.1.1.1), and ntp_amplification_worker (monlist requests reflected off time.google.com and pool.ntp.org). An auto-scaling controller checks observed RPS every 15 seconds and grows the worker pool (current x 1.2 + 10, capped at 2,000 threads, up to 1,000 initial threads with 1ms minimum per-worker delay) whenever throughput falls below 70% of the operator-set target. A seven-source proxy harvesting/validation pipeline (api.proxyscrape.com, proxylist.geonode.com, free-proxy-list.net, and four unnamed GitHub raw-file sources) validates candidates against httpbin.org/ip with a 5-second timeout, retaining only sub-2-second responders, and supports live rotation via the /proxy Telegram command.

Operator access is gated by a SQLite-backed (c2.db) single-use license-key system: keys are generated with secrets.token_hex(10) into 20-character hex strings, default max-uses of 1, with admin commands /key [days], /keys, and /delkey — consistent with a tiered-access or resale/reseller distribution model typical of low-tier booter/stresser markets. The Telegram bot itself is gated by a hardcoded operator Telegram ID (7593738229) and a fixed plaintext password ("7788") accepted by the /login command, tracked in a logged_in session dictionary; /attacks, /proxy, /key, /cvv, /stats round out the command surface, with periodic in-chat stats messages during active floods.

Observed live attack sessions recovered from the leaked artifacts show operational use against shopmuabancf[.]com (an e-commerce site, 20,000 RPS combo attack, 10,404 requests, successful), Bloomberg.com (200,000 RPS combo attack, watchdog declared the target dead with 0 completed requests logged), and Trangchubloxfruit[.]com (a Roblox/gaming-adjacent site, 50,000 RPS combo attack, only 132 requests — low throughput). Vietnamese-language comments and bot response strings throughout the source point to a Vietnamese-speaking developer/operator community; overall sophistication is assessed as low, consistent with widespread booter/stresser tooling rather than an advanced or state-linked capability.

The later (April 29) variant adds three server-side modules whose end-to-end functionality Flare could not confirm because the corresponding client binary (client.py) was absent from the leaked artifacts: (1) a wireless-attack module wrapping aireplay-ng and netsh wlan disconnect for WiFi deauthentication, l2ping -f / hcitool dc for Bluetooth disruption (Linux-only, requires root), netsh wlan show profiles key=clear / nmcli for saved WiFi credential extraction, and a three-stage hcxdumptool -> hcxpcapngtool -> hashcat WiFi-cracking workflow; (2) a credential/financial-data module exposing manual /cvv <cc> <cvv> <exp> entry into a cvv_logs table (cc, cvv, exp, time) retrievable via /getcvv, a /wifipass command for extracted WiFi profiles, and a referenced but unimplemented "browser_steal" task type with no corresponding parsing code; and (3) a Flask-based botnet-tasking layer exposing /slave_register, /slave_get_task, and /slave_report endpoints, a BOTNET_HIERARCHY structure tracking masters/slaves/task queues/completions, task types wifi_scan, browser_steal, and full_steal, and Telegram commands /botnet_task, /botnetdata, /botnetslaves, /botnetexport. Flare assessed this later feature set as still in a feature-testing phase given the missing client component.

No CVE or software vulnerability underlies this threat — it is a commodity attack tool/campaign. Its practical risk is availability impact from Layer 3/4/7 DDoS at meaningful scale (validated against a Bloomberg-class target), a low barrier to entry via public Pastebin distribution and license-key resale, and an emerging trajectory toward broader botnet C2 and credential-theft capability that defenders should track even while unconfirmed.

MITRE ATT&CK techniques used in TL-2026-1592

Collection

T1005 Data from Local System; T1119 Automated Collection

Discovery

T1016 System Network Configuration Discovery; T1518 Software Discovery

Exfiltration

T1041 Exfiltration Over C2 Channel

Execution

T1059 Command and Scripting Interpreter

Command and Control

T1071 Application Layer Protocol; T1102 Web Service

command-and-control

T1090 Proxy

Impact

T1498 Network Denial of Service; T1499 Endpoint Denial of Service

Credential Access

T1552 Unsecured Credentials; T1555 Credentials from Password Stores; T1557 Adversary-in-the-Middle

Resource Development

T1583 Acquire Infrastructure; T1585 Establish Accounts; T1588 Obtain Capabilities

Reconnaissance

T1590 Gather Victim Network Information

Remediation for NULLZEREPTOOL

Immediate actions

  • Deploy or verify upstream DDoS scrubbing / CDN-based mitigation (rate limiting, WAF challenge pages) for internet-facing web properties
  • Block or rate-limit inbound UDP responses from open DNS resolvers (8.8.8.8, 1.1.1.1) and NTP servers (pool.ntp.org, time.google.com) at perimeter where reflection abuse is suspected
  • Alert on abnormal outbound connections to api.telegram.org from unexpected hosts/processes as a potential bot-C2 indicator
  • Monitor egress to known free-proxy aggregator domains (api.proxyscrape.com, proxylist.geonode.com, free-proxy-list.net) from server/workstation subnets
  • Disable or tightly restrict OS-level WiFi credential export commands (netsh wlan show profiles key=clear, nmcli) via endpoint policy on hosts that do not require them

Workarounds

  • Where DDoS scrubbing is unavailable, pre-stage IP allow-listing / geofencing for critical services known to be targeted (e-commerce, media, gaming)
  • Rotate and monitor any exposed CVV/payment-capture forms for signs of manual data exfiltration consistent with the tool's /cvv workflow

Longer-term hardening

  • Enforce BCP38/BCP84 (source-address validation) and disable open recursive DNS/NTP monlist responses on owned infrastructure to reduce amplification abuse
  • Deploy network behavior analytics/EDR rules for slowloris-style partial-header connection holding and combo-style multi-protocol flood signatures
  • Track Pastebin/paste-site and Telegram-channel leak monitoring feeds for reappearance of NULLZEREPTOOL variants or forks
  • Harden WiFi deployments (WPA3, 802.11w management-frame protection) against deauthentication-based disruption
  • Extend threat-hunting playbooks to cover Flask-based slave/botnet registration endpoints if internal hosts are suspected of running the later variant's server component

Timeline of NULLZEREPTOOL

  • Earlier NULLZEREPTOOL variant uploaded to Pastebin under paste ID Rxk4VgnX, discovered by Flare via banner/keyword search of monitored paste sites.
  • Analysis of the leaked c2.db and bot command surface (/key, /keys, /delkey) reveals a SQLite-backed single-use license-key system generated via secrets.token_hex(10), indicating a tiered-access or reseller distribution model typical of low-tier booter/stresser markets.
  • Flare identifies three new server-side modules (wireless-attack, credential/CVV harvesting, Flask botnet-tasking layer) added in the later variant, but assesses them as an unconfirmed, still-in-testing feature set because the corresponding client.py binary is absent from the leaked artifacts.
  • Recovered operator logs show a 50,000 RPS combo-method DDoS session against gaming-adjacent site trangchubloxfruit.com, yielding only 132 requests (low throughput).
  • Recovered operator logs show a 200,000 RPS combo-method DDoS session targeting Bloomberg.com; the tool's own watchdog declared the target dead with 0 completed requests recorded.
  • Recovered operator logs show a 20,000 RPS combo-method DDoS session against e-commerce site shopmuabancf.com, reaching 10,404 requests and assessed successful.
  • Flare analysts confirm and begin technical analysis of the leaked NULLZEREPTOOL source across both variants.
  • Later, more complete NULLZEREPTOOL variant (paste ID ryxQ077S) posted to Pastebin, flagged by Flare's automated source-code leak monitoring.
  • Flare publishes public technical analysis of NULLZEREPTOOL, disclosing the DDoS engine, C2 mechanics, license-key model, and later variant's unconfirmed wireless/credential/botnet modules.

Sources cited for NULLZEREPTOOL

Detection coverage for TL-2026-1592

As of 2026-07-21, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1592 across Splunk SPL, Microsoft KQL and Sigma, covering 29 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
29 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats