Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
16 distinct techniques documented for this family, organized by ATT&CK tactic.
WiFi password extraction is implemented as a series of OS command invocations... extracts each password with 'netsh wlan show profile name=<SSID> key=clear'... On Linux, the handler uses nmcli to query connection details and extract the PSK.
WiFi cracking is implemented as a three-stage workflow: hcxdumptool captures handshakes...
WiFi password extraction is implemented as a series of OS command invocations... On Windows, the handler reads all saved profiles via netsh wlan show profiles, then extracts each password... On Linux, the handler uses nmcli to query connection details and extract the PSK.
NULLZEREPTOOL is a Python-based attack framework controlled via Telegram... The bot uses telebot.Telebot with the hard-coded token.
Flare recommends that security teams watch for... DNS or NTP amplification traffic hitting resolvers like 8.8.8.8, 1.1.1.1, time.google.com, and pool.ntp.org. | NULLZEREPTOOL is a newly uncovered attack framework that turns a Telegram bot into a remote control panel for powerful distributed denial of service campaigns backed by rotating proxy infrastructure.
Flare recommends that security teams watch for mixed HTTP methods with random headers, high volume UDP and TCP bursts to ports 80 and 443...
12 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
Other indicator types observed in public reporting.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Telegram-controlled attack framework centered on DDoS operations. It supports multiple flood methods, rotating proxy harvesting and validation, operator control via Telegram commands, and experimental modules for WiFi deauthentication, Bluetooth disruption, credential/CVV handling, and a not-yet-mature hierarchical botnet tasking model.
A Python-based Telegram-controlled attack framework with a fully implemented DDoS engine, proxy rotation pipeline, Flask-based C2/API, and access-key management. A later variant adds coded but unconfirmed wireless attack, WiFi password extraction/cracking, Bluetooth disruption, and hierarchical botnet tasking features; many of these additions were present only in server-side code and not observed end-to-end.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.