researchmate.net A.I CyberSecurity Scoring
researchmate.net
Company Information
Website:https://researchmate.net
Employees number:10
Number of followers:515
NAICS:5112
Industry Type:Software Development
Homepage:researchmate.net
researchmate.net Risk Score (AI oriented)
Between 700 and 749
researchmate.netSoftware Development
Updated:
22/07/2026
22/07/2026
732/1000
Moderate
Ba
researchmate.net Global Score (TPRM)
xxxx
researchmate.netSoftware Development
Score locked

researchmate.netModerate
Current Score
732Ba (MODERATE)
01000
1 incidents
-18 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
AUGUST 2026
732
JULY 2026
750
Cyber Attack
22 Jul 2026 • researchmate.net
Bloomberg and daula: New NULLZEREPTOOL Uses Telegram to Launch 20 DDoS Methods With Rotating Proxies
New Telegram-Based DDoS Framework NULLZEREPTOOL Uncovered
732
LOW-18
BLORES1784723059
New Telegram-Based DDoS Framework NULLZEREPTOOL Uncovered
Researchers at Flare have identified NULLZEREPTOOL, a sophisticated attack framework that repurposes a Telegram bot as a remote control panel for distributed denial-of-service (DDoS) campaigns, leveraging rotating proxy infrastructure to evade detection.
The framework was first discovered after a Pastebin post was flagged during routine monitoring, exposing the full Python source code of a Telegram-managed DDoS bot. While initially appearing as a basic script, further analysis revealed a multi-layered design combining a proven DDoS engine with experimental modules for WiFi disruption, Bluetooth jamming, and credential theft.
### Key Features & Capabilities
- Telegram-Controlled DDoS Panel: Unlike traditional self-spreading botnets, NULLZEREPTOOL operates as a command-and-control (C2) hub via Telegram, allowing attackers to launch floods, adjust worker threads, and monitor attack statistics in real time.
- 20+ Attack Methods: The framework supports HTTP GET floods, UDP packets, TCP handshakes, and a "combo" attack bundling multiple request types to maximize impact.
- Proxy Rotation: To sustain attacks, NULLZEREPTOOL harvests free HTTP proxies from seven sources (e.g., api.proxyscrape.com, proxylist.geonode.com), validating and rotating them to bypass IP-based rate limits.
- Experimental Modules: Later variants include WiFi deauthentication, Bluetooth jamming, and hierarchical botnet tasking, though these features remain unproven in real-world attacks due to missing client components.
- Credential & Data Handling: The framework includes CVV logging, password extraction, and a "BOTNET_HIERARCHY" structure for potential future botnet expansion, though current implementations are server-side only.
### Attack Workflow & Testing
- Test Targets: Operators conducted live tests against sites like shopmuabancf[.]com, Bloomberg[.]com/quote/FRGH:SW, and daula[.]shop, tracking worker counts and request volumes.
- Proxy & Amplification Tactics: The framework abuses public DNS resolvers (8.8.8.8, 1.1.1.1) and NTP servers (time.google.com, pool.ntp.org) for amplification attacks.
- "Quantum" Branding Misleading: Despite claims of "advanced" WiFi/Bluetooth exploits, the code relies on standard cryptographic functions (e.g., hashlib.sha3_512), suggesting marketing hype rather than genuine innovation.
### Defensive Insights
Flare’s analysis highlights how lightweight, chat-driven orchestration (e.g., Telegram bots) can be weaponized for agile DDoS attacks. Organizations should monitor for:
- Mixed HTTP methods with random headers
- High-volume UDP/TCP bursts on ports 80/443
- DNS/NTP amplification traffic targeting public resolvers
The discovery underscores the need for continuous monitoring of paste sites, dark web forums, and Telegram channels to detect emerging threats before they mature into full-fledged attack platforms. Hardcoded bot tokens, admin IDs, and C2 endpoints have been identified and can be used for detection and blocking.
### Indicators of Compromise (IoCs)
- Target Domains: shopmuabancf[.]com, shopbloxfruits[.]com, Bloomberg[.]com/quote/FRGH:SW
- Proxy Sources: api.proxyscrape[.]com, proxylist.geonode[.]com, free-proxy-list[.]net
- Amplification Targets: 8.8.8.8, 1.1.1.1, time.google.com, pool.ntp.org
- Telegram Credentials: Hardcoded BOT_TOKEN, ADMIN_ID (7593738229), ADMIN_PASSWORD ("7788")
- Source Code Links: Pastebin.com/ryxQ077S (later variant), Pastebin.com/Rxk4VgnX (earlier variant)
INCIDENT DETAILS -
TYPE
IMPACT
DATA BREACH
REFERENCES
JUNE 2026
750
MAY 2026
750
APRIL 2026
750
MARCH 2026
750
FEBRUARY 2026
750
JANUARY 2026
750
DECEMBER 2025
750
NOVEMBER 2025
750
OCTOBER 2025
750
SEPTEMBER 2025
750
Frequently Asked Questions
?
What is the current A.I Rankiteo Cyber Score for researchmate.net ??
What was researchmate.net's A.I Rankiteo Cyber Score in July 2026 ??
What was researchmate.net's A.I Rankiteo Cyber Score in June 2026 ??
What was researchmate.net's A.I Rankiteo Cyber Score in May 2026 ??
What was researchmate.net's A.I Rankiteo Cyber Score in April 2026 ??
What was researchmate.net's A.I Rankiteo Cyber Score in March 2026 ??
What was researchmate.net's A.I Rankiteo Cyber Score in February 2026 ??
What was researchmate.net's A.I Rankiteo Cyber Score in January 2026 ??
What was researchmate.net's A.I Rankiteo Cyber Score in December 2025 ??
What was researchmate.net's A.I Rankiteo Cyber Score in November 2025 ??
What was researchmate.net's A.I Rankiteo Cyber Score in October 2025 ??
What was researchmate.net's A.I Rankiteo Cyber Score in September 2025 ??
What is the average per-incident point impact on researchmate.net's A.I Rankiteo Cyber Score over the past 12 months ??
Where can I access detailed records of all cyber incidents associated with researchmate.net ??
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ??
Where can I view researchmate.net's profile page on Rankiteo ??
How accurate is the A.I Rankiteo Risk Scoring methodology ?