Bloomberg and daula: New NULLZEREPTOOL Uses Telegram to Launch 20 DDoS Methods With Rotating Proxies

Bloomberg and daula: New NULLZEREPTOOL Uses Telegram to Launch 20 DDoS Methods With Rotating Proxies

New Telegram-Based DDoS Framework NULLZEREPTOOL Uncovered

Researchers at Flare have identified NULLZEREPTOOL, a sophisticated attack framework that repurposes a Telegram bot as a remote control panel for distributed denial-of-service (DDoS) campaigns, leveraging rotating proxy infrastructure to evade detection.

The framework was first discovered after a Pastebin post was flagged during routine monitoring, exposing the full Python source code of a Telegram-managed DDoS bot. While initially appearing as a basic script, further analysis revealed a multi-layered design combining a proven DDoS engine with experimental modules for WiFi disruption, Bluetooth jamming, and credential theft.

Key Features & Capabilities

  • Telegram-Controlled DDoS Panel: Unlike traditional self-spreading botnets, NULLZEREPTOOL operates as a command-and-control (C2) hub via Telegram, allowing attackers to launch floods, adjust worker threads, and monitor attack statistics in real time.
  • 20+ Attack Methods: The framework supports HTTP GET floods, UDP packets, TCP handshakes, and a "combo" attack bundling multiple request types to maximize impact.
  • Proxy Rotation: To sustain attacks, NULLZEREPTOOL harvests free HTTP proxies from seven sources (e.g., api.proxyscrape.com, proxylist.geonode.com), validating and rotating them to bypass IP-based rate limits.
  • Experimental Modules: Later variants include WiFi deauthentication, Bluetooth jamming, and hierarchical botnet tasking, though these features remain unproven in real-world attacks due to missing client components.
  • Credential & Data Handling: The framework includes CVV logging, password extraction, and a "BOTNET_HIERARCHY" structure for potential future botnet expansion, though current implementations are server-side only.

Attack Workflow & Testing

  • Test Targets: Operators conducted live tests against sites like shopmuabancf[.]com, Bloomberg[.]com/quote/FRGH:SW, and daula[.]shop, tracking worker counts and request volumes.
  • Proxy & Amplification Tactics: The framework abuses public DNS resolvers (8.8.8.8, 1.1.1.1) and NTP servers (time.google.com, pool.ntp.org) for amplification attacks.
  • "Quantum" Branding Misleading: Despite claims of "advanced" WiFi/Bluetooth exploits, the code relies on standard cryptographic functions (e.g., hashlib.sha3_512), suggesting marketing hype rather than genuine innovation.

Defensive Insights

Flare’s analysis highlights how lightweight, chat-driven orchestration (e.g., Telegram bots) can be weaponized for agile DDoS attacks. Organizations should monitor for:

  • Mixed HTTP methods with random headers
  • High-volume UDP/TCP bursts on ports 80/443
  • DNS/NTP amplification traffic targeting public resolvers

The discovery underscores the need for continuous monitoring of paste sites, dark web forums, and Telegram channels to detect emerging threats before they mature into full-fledged attack platforms. Hardcoded bot tokens, admin IDs, and C2 endpoints have been identified and can be used for detection and blocking.

Indicators of Compromise (IoCs)

"id": "blores1784723059",
"linkid": "bloomberg-news, researchmate-net",
"type": "Cyber Attack",
"date": "7/2026",
"severity": "25",
"impact": "1",
"explanation": "Attack without any consequences"
{'affected_entities': [{'name': 'shopmuabancf[.]com', 'type': 'Website'},
                       {'industry': 'Financial',
                        'name': 'Bloomberg[.]com/quote/FRGH:SW',
                        'type': 'Website'},
                       {'name': 'daula[.]shop', 'type': 'Website'},
                       {'name': 'shopbloxfruits[.]com', 'type': 'Website'}],
 'attack_vector': 'Telegram bot (C2), Proxy rotation, DNS/NTP amplification',
 'data_breach': {'personally_identifiable_information': 'Potential '
                                                        '(credentials)',
                 'sensitivity_of_data': 'High',
                 'type_of_data_compromised': ['CVV data', 'Passwords']},
 'description': 'Researchers at Flare identified NULLZEREPTOOL, a '
                'sophisticated attack framework that repurposes a Telegram bot '
                'as a remote control panel for distributed denial-of-service '
                '(DDoS) campaigns, leveraging rotating proxy infrastructure to '
                'evade detection. The framework includes multi-layered design '
                'combining a proven DDoS engine with experimental modules for '
                'WiFi disruption, Bluetooth jamming, and credential theft.',
 'impact': {'data_compromised': 'CVV logging, password extraction',
            'identity_theft_risk': 'Potential risk due to credential theft',
            'operational_impact': 'Potential service disruption due to DDoS '
                                  'attacks',
            'payment_information_risk': 'Potential risk due to CVV logging'},
 'investigation_status': 'Completed (analysis published)',
 'lessons_learned': 'Lightweight, chat-driven orchestration (e.g., Telegram '
                    'bots) can be weaponized for agile DDoS attacks. '
                    'Continuous monitoring of paste sites, dark web forums, '
                    'and Telegram channels is essential to detect emerging '
                    'threats.',
 'post_incident_analysis': {'corrective_actions': 'Block IoCs, monitor for '
                                                  'Telegram-based C2 activity, '
                                                  'and enhance DDoS mitigation '
                                                  'strategies',
                            'root_causes': 'Exposure of Python source code via '
                                           'Pastebin, repurposing of Telegram '
                                           'bots for C2, abuse of public '
                                           'proxies and amplification '
                                           'services'},
 'recommendations': ['Monitor for mixed HTTP methods with random headers',
                     'Monitor for high-volume UDP/TCP bursts on ports 80/443',
                     'Monitor for DNS/NTP amplification traffic targeting '
                     'public resolvers',
                     'Block identified IoCs (e.g., hardcoded bot tokens, admin '
                     'IDs, C2 endpoints)'],
 'references': [{'source': 'Flare Research'},
                {'source': 'Pastebin', 'url': 'Pastebin.com/ryxQ077S'},
                {'source': 'Pastebin', 'url': 'Pastebin.com/Rxk4VgnX'}],
 'response': {'enhanced_monitoring': 'Monitor for mixed HTTP methods with '
                                     'random headers, high-volume UDP/TCP '
                                     'bursts on ports 80/443, and DNS/NTP '
                                     'amplification traffic'},
 'title': 'New Telegram-Based DDoS Framework NULLZEREPTOOL Uncovered',
 'type': 'DDoS'}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.