NightmareStresser DDoS Service Disrupted in International Operation
FBI seized NightmareStresser DDoS-for-hire domains in Operation PowerOFF; the booter had nearly 1 million users and launched hundreds of thousands of attacks since 2022.
The US Department of Justice announced the FBI seized nightmare-stresser[.]com and nightmarestresser[.]org, disrupting one of the longest-running DDoS-for-hire services as part of Operation PowerOFF. The service was active since at least 2022, possibly founded in 2016, could launch 3,000-4,000 attacks per hour, accepted cryptocurrency, and reached nearly 1 million users by 2025. Over the past eight years the US has charged 12 DDoS facilitators and seized more than 100 booter domains.
- FBI seized nightmare-stresser[.]com and nightmarestresser[.]org under Operation PowerOFF
- Service launched 3,000-4,000 attacks per hour and accepted cryptocurrency
- Nearly 1 million users by 2025; active since at least 2022
- US charged 12 DDoS facilitators and seized 100+ booter domains in eight years
Indicators of compromiseauto-extracted · verify before use · export allAll →
| Type | Indicator | Context |
|---|---|---|
| domain | nightmare-stresser.com | net domains associated with the booter service. Visitors to nightmare-stresser[.]com and nightmarestresser[.]org are now served a seizure bann |
| domain | nightmarestresser.org | he booter service. Visitors to nightmare-stresser[.]com and nightmarestresser[.]org are now served a seizure banner. Authorities said Nightma |
Full article313 words · extracted from securityweek.com · click to collapse
NightmareStresser, one of the longest-running distributed denial-of-service (DDoS) for-hire services in the world, has been disrupted.
The US Department of Justice announced this week that the FBI has seized the internet domains associated with the booter service.
Visitors to nightmare-stresser[.]com and nightmarestresser[.]org are now served a seizure banner.
Authorities said NightmareStresser had been active since at least 2022 and was used to launch hundreds of thousands of DDoS attacks against victims worldwide.
However, security researcher Alex Carter reported last year that NightmareStresser was likely founded in 2016 and became popular in 2018, after rival services were disrupted, becoming the largest DDoS tool in 2019.
By 2025, it had grown to nearly 1 million users. It could launch between 3,000 and 4,000 attacks per hour, accepted cryptocurrency payments, but avoided government, education, and hospital domains.
Advertisement. Scroll to continue reading.
The NightmareStresser takedown was part of Operation PowerOFF, a coordinated global effort to dismantle DDoS-for-hire infrastructures globally and hold the individuals behind these services accountable.
DDoS-for-hire services, also referred to as booters or stressers, have been proliferating over the past years, as they represent low-entry barriers for cybercriminal-wannabes, the DoJ notes.
Over the past eight years, the US charged 12 DDoS attack facilitators and seized over 100 domains associated with booter services.
In April, law enforcement agencies in 21 countries disrupted 53 domains associated with DDoS-for-hire services. Last year, the US disrupted the RapperBot DDoS botnet, and 27 websites linked to booter services were seized in 2024.
In addition to disrupting DDoS-for-hire infrastructure, law enforcement agencies have been tracking and charging both the administrators and the users of these services.
Related: 23-Year-Old Sality P2P Botnet Disrupted
Related: US Disrupts Chinese Hacking Platform Used in Military and Critical Infrastructure Attacks
Related: Google, FBI Disrupt NetNut Residential Proxy Network Powered by Millions of Devices
Related: 15,000 WordPress Websites Cleaned Up in SocGholish Botnet Takedown
Text extracted automatically; images, tables and formatting may be missing. Original: https://www.securityweek.com/nightmarestresser-ddos-service-disrupted-in-international-operation/