# NULLZEREPTOOL: Telegram-Controlled Python DDoS and Multi-Function Attack Framework

> NULLZEREPTOOL is a Python-based, Telegram-controlled DDoS-as-a-Service framework surfaced through two Pastebin source-code leaks (April 27 and April 29, 2026). It ships a 20-method Layer 3/4/7 DDoS engine with auto-scaling and proxy rotation behind a hardcoded Telegram bot C2 and single-use license-key access model; the later variant adds unconfirmed server-side wireless-attack, credential-extraction, and botnet-tasking modules.

- **Published:** 2026-07-21T00:00:00Z
- **Last reviewed:** 2026-07-21T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-1592
- **ID:** TL-2026-1592
- **Severity:** MEDIUM
- **Category:** MALWARE
- **Status:** ACTIVE
- **Detections:** 9 · **IOCs:** 29 (full data via the Threadlinqs MCP server — Purple tier)

## Description

NULLZEREPTOOL is a commodity DDoS-as-a-Service (DDoSaaS) tool written in Python and controlled entirely through a Telegram bot (via the `telebot` library), discovered by Flare's dark-web/paste-site monitoring across two separate Pastebin uploads two days apart (Rxk4VgnX on 2026-04-27, ryxQ077S on 2026-04-29). The core is a 20-method attack engine dispatched from a METHODS dictionary, including combo_worker (interleaved HTTP/UDP/TCP), http_worker, udp_worker, tcp_worker, slowloris_worker, dns_amplification_worker (50x repeated queries reflected off 8.8.8.8 and 1.1.1.1), and ntp_amplification_worker (monlist requests reflected off time.google.com and pool.ntp.org). An auto-scaling controller checks observed RPS every 15 seconds and grows the worker pool (current x 1.2 + 10, capped at 2,000 threads, up to 1,000 initial threads with 1ms minimum per-worker delay) whenever throughput falls below 70% of the operator-set target. A seven-source proxy harvesting/validation pipeline (api.proxyscrape.com, proxylist.geonode.com, free-proxy-list.net, and four unnamed GitHub raw-file sources) validates candidates against httpbin.org/ip with a 5-second timeout, retaining only sub-2-second responders, and supports live rotation via the /proxy Telegram command.

Operator access is gated by a SQLite-backed (c2.db) single-use license-key system: keys are generated with secrets.token_hex(10) into 20-character hex strings, default max-uses of 1, with admin commands /key [days], /keys, and /delkey — consistent with a tiered-access or resale/reseller distribution model typical of low-tier booter/stresser markets. The Telegram bot itself is gated by a hardcoded operator Telegram ID (7593738229) and a fixed plaintext password ("7788") accepted by the /login command, tracked in a logged_in session dictionary; /attacks, /proxy, /key, /cvv, /stats round out the command surface, with periodic in-chat stats messages during active floods.

Observed live attack sessions recovered from the leaked artifacts show operational use against shopmuabancf[.]com (an e-commerce site, 20,000 RPS combo attack, 10,404 requests, successful), Bloomberg.com (200,000 RPS combo attack, watchdog declared the target dead with 0 completed requests logged), and Trangchubloxfruit[.]com (a Roblox/gaming-adjacent site, 50,000 RPS combo attack, only 132 requests — low throughput). Vietnamese-language comments and bot response strings throughout the source point to a Vietnamese-speaking developer/operator community; overall sophistication is assessed as low, consistent with widespread booter/stresser tooling rather than an advanced or state-linked capability.

The later (April 29) variant adds three server-side modules whose end-to-end functionality Flare could not confirm because the corresponding client binary (client.py) was absent from the leaked artifacts: (1) a wireless-attack module wrapping aireplay-ng and netsh wlan disconnect for WiFi deauthentication, l2ping -f / hcitool dc for Bluetooth disruption (Linux-only, requires root), netsh wlan show profiles key=clear / nmcli for saved WiFi credential extraction, and a three-stage hcxdumptool -> hcxpcapngtool -> hashcat WiFi-cracking workflow; (2) a credential/financial-data module exposing manual /cvv <cc> <cvv> <exp> entry into a cvv_logs table (cc, cvv, exp, time) retrievable via /getcvv, a /wifipass command for extracted WiFi profiles, and a referenced but unimplemented "browser_steal" task type with no corresponding parsing code; and (3) a Flask-based botnet-tasking layer exposing /slave_register, /slave_get_task, and /slave_report endpoints, a BOTNET_HIERARCHY structure tracking masters/slaves/task queues/completions, task types wifi_scan, browser_steal, and full_steal, and Telegram commands /botnet_task, /botnetdata, /botnetslaves, /botnetexport. Flare assessed this later feature set as still in a feature-testing phase given the missing client component.

No CVE or software vulnerability underlies this threat — it is a commodity attack tool/campaign. Its practical risk is availability impact from Layer 3/4/7 DDoS at meaningful scale (validated against a Bloomberg-class target), a low barrier to entry via public Pastebin distribution and license-key resale, and an emerging trajectory toward broader botnet C2 and credential-theft capability that defenders should track even while unconfirmed.

## MITRE ATT&CK

- T1590 Gather Victim Network Information
- T1588 Obtain Capabilities
- T1583 Acquire Infrastructure
- T1585 Establish Accounts
- T1059 Command and Scripting Interpreter
- T1090 Proxy
- T1552 Unsecured Credentials
- T1555 Credentials from Password Stores
- T1557 Adversary-in-the-Middle
- T1016 System Network Configuration Discovery
- T1518 Software Discovery
- T1119 Automated Collection
- T1005 Data from Local System
- T1102 Web Service
- T1071 Application Layer Protocol
- T1041 Exfiltration Over C2 Channel
- T1498 Network Denial of Service
- T1499 Endpoint Denial of Service

## Sources

- [NULLZEREPTOOL: Telegram-Controlled DDoS & Multi-Function Attack Framework](https://flare.io/learn/resources/blog/nullzereptool-telegram-controlled-ddos-multi-function-attack-framework)
- [Source Code Leak Monitoring](https://flare.io/glossary/source-code-leak-monitoring)
- [How Telegram Is Powering the New Age of DDoS](https://falconfeeds.io/blogs/telegram-ddos-defacement-hacker-claims/)
- [The Great Exodus to Telegram: A Tour of the New Cybercrime Underground](https://www.bleepingcomputer.com/news/security/the-great-exodus-to-telegram-a-tour-of-the-new-cybercrime-underground/)
- [DDoS-as-a-Service: The Rebirth Botnet](https://www.sysdig.com/blog/ddos-as-a-service-the-rebirth-botnet)
- [MITRE ATT&CK T1498: Network Denial of Service](https://attack.mitre.org/techniques/T1498/)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-1592
