US Major Takedown of NightmareStresser DDoS-for-Hire Service
US authorities dismantle NightmareStresser DDoS-for-hire infrastructure
US authorities dismantle NightmareStresser DDoS-for-hire infrastructure
On Tuesday, the U.S. Federal Bureau of Investigation (FBI) executed a domain seizure targeting NightmareStresser, a persistent distributed denial-of-service (DDoS) platform operational for years. The service functioned as a DDoS-for-hire mechanism, enabling users to access botnets composed of compromised routers and internet of things (IoT) devices to conduct large-scale attacks against online systems. Prior to its shutdown, the platform marketed itself as the “top online IP booter” and claimed to offer 24/7 availability for DDoS operations.
Operation PowerOFF and international collaboration
According to the FBI Cyber Division, NightmareStresser had facilitated hundreds of thousands of DDoS attacks globally since 2022. The agency emphasized that the takedown was part of Operation PowerOFF, an international law enforcement initiative focused on disrupting criminal DDoS-for-hire networks. A notice on the seized domains now states that the action aligns with this collaborative effort.
Previous seizures and arrests
In December 2022, the U.S. Department of Justice (DOJ) previously seized the nightmarestresser.com domain and arrested six individuals linked to multiple DDoS-for-hire services. Operation PowerOFF, launched in December 2018, has since targeted numerous DDoS-as-a-service platforms. The operation previously resulted in the removal of the DigitalStress service in the UK, the seizure of the Dstat.cc review platform, and the arrest of two operators in Poland.
Recent enforcement actions
Additional enforcement actions under Operation PowerOFF have led to the seizure of 13 domains and 48 more hosting booter services across two waves. In 2023, Polish authorities detained four suspects connected to six DDoS-for-hire platforms responsible for attacks on schools, government agencies, businesses, and gaming services. Concurrently, U.S. authorities seized nine domains as part of the same operation.
Scale and impact of NightmareStresser
The FBI highlighted that NightmareStresser’s infrastructure had been a significant source of malicious activity, with cybersecurity firm Searchlight Cyber reporting over 566,000 users in 2023. The platform’s operational timeline and scale underscore the persistent threat posed by DDoS-for-hire services, which remain a critical concern for global cybersecurity efforts.
According to the FBI Cyber Division, NightmareStresser had facilitated hundreds of thousands of DDoS attacks globally since 2022.
