Researchers analyzed NULLZEREPTOOL, a Python-based attack framework exposed in Pastebin posts, and found a Telegram-controlled platform focused primarily on distributed denial-of-service operations. The tool links two source-code variants through shared credentials and core logic: an earlier build centered on DDoS and proxy management, and a later version that retained the same attack engine while expanding into additional modules. Analysis showed support for 20 DDoS methods, Telegram-based command and control, proxy harvesting and validation, a Flask API, key management, and logging tied to payment-card data, with evidence that the framework was tested against several websites.
The newer code also introduced wireless attack functions, credential-related features, and a hierarchical botnet tasking model, but researchers said many of those additions appear incomplete or unproven. Flare found that the DDoS engine, Telegram C2, and proxy pipeline were implemented in source, while the WiFi, Bluetooth, credential-theft, and broader botnet capabilities appeared to depend on missing client artifacts or external tooling. The assessment concludes that NULLZEREPTOOL is best understood as a low-tier, Telegram-managed DDoS panel showing signs of malware-as-a-service feature expansion rather than a confirmed advanced botnet or wireless exploitation platform.

Get the actors, campaigns, and ATT&CK mapping behind it.
3 events from the most recent confirmed update back to the earliest known activity.
Analysis of the exposed code found NULLZEREPTOOL to be a Telegram-controlled attack framework with DDoS orchestration, rotating proxies, and related infrastructure. Researchers linked the later code to the earlier variant through shared credentials and core logic, while assessing many expanded features as unconfirmed or immature.
A second Pastebin post on April 29, 2026 exposed a later NULLZEREPTOOL code variant. It retained the DDoS core while adding wireless attack modules, credential-related functions, and a hierarchical botnet tasking model in server-side code.
Researchers identified an earlier Python-based NULLZEREPTOOL variant from a Pastebin post on April 27, 2026. This version was centered on DDoS functionality and proxy management.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 12 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.