ZeroHour
SecurityWeekpublished ()ingested Ionut Arghire
Part of a story covered by 8 sources: “U.S. Seizes NightmareStresser DDoS-for-Hire Domains in Operation PowerOFF” — merged summary and timeline →

NightmareStresser DDoS Service Disrupted in International Operation

infoPolicy & legal exploited in the wildimportance 62
AI summary · glm-5.3-flash

FBI seized NightmareStresser DDoS-for-hire domains in Operation PowerOFF; the booter had nearly 1 million users and launched hundreds of thousands of attacks since 2022.

The US Department of Justice announced the FBI seized nightmare-stresser[.]com and nightmarestresser[.]org, disrupting one of the longest-running DDoS-for-hire services as part of Operation PowerOFF. The service was active since at least 2022, possibly founded in 2016, could launch 3,000-4,000 attacks per hour, accepted cryptocurrency, and reached nearly 1 million users by 2025. Over the past eight years the US has charged 12 DDoS facilitators and seized more than 100 booter domains.

  • FBI seized nightmare-stresser[.]com and nightmarestresser[.]org under Operation PowerOFF
  • Service launched 3,000-4,000 attacks per hour and accepted cryptocurrency
  • Nearly 1 million users by 2025; active since at least 2022
  • US charged 12 DDoS facilitators and seized 100+ booter domains in eight years

Indicators of compromiseAll →

TypeIndicatorContext
domainnightmare-stresser.comnet domains associated with the booter service. Visitors to nightmare-stresser[.]com and nightmarestresser[.]org are now served a seizure bann
domainnightmarestresser.orghe booter service. Visitors to nightmare-stresser[.]com and nightmarestresser[.]org are now served a seizure banner. Authorities said Nightma
Full article313 words · extracted from securityweek.com · click to collapse

NightmareStresser, one of the longest-running distributed denial-of-service (DDoS) for-hire services in the world, has been disrupted.

The US Department of Justice announced this week that the FBI has seized the internet domains associated with the booter service.

Visitors to nightmare-stresser[.]com and nightmarestresser[.]org are now served a seizure banner.

Authorities said NightmareStresser had been active since at least 2022 and was used to launch hundreds of thousands of DDoS attacks against victims worldwide.

However, security researcher Alex Carter reported last year that NightmareStresser was likely founded in 2016 and became popular in 2018, after rival services were disrupted, becoming the largest DDoS tool in 2019.

By 2025, it had grown to nearly 1 million users. It could launch between 3,000 and 4,000 attacks per hour, accepted cryptocurrency payments, but avoided government, education, and hospital domains.

Advertisement. Scroll to continue reading.

The NightmareStresser takedown was part of Operation PowerOFF, a coordinated global effort to dismantle DDoS-for-hire infrastructures globally and hold the individuals behind these services accountable.

DDoS-for-hire services, also referred to as booters or stressers, have been proliferating over the past years, as they represent low-entry barriers for cybercriminal-wannabes, the DoJ notes.

Over the past eight years, the US charged 12 DDoS attack facilitators and seized over 100 domains associated with booter services.

In April, law enforcement agencies in 21 countries disrupted 53 domains associated with DDoS-for-hire services. Last year, the US disrupted the RapperBot DDoS botnet, and 27 websites linked to booter services were seized in 2024.

In addition to disrupting DDoS-for-hire infrastructure, law enforcement agencies have been tracking and charging both the administrators and the users of these services.

Related: 23-Year-Old Sality P2P Botnet Disrupted

Related: US Disrupts Chinese Hacking Platform Used in Military and Critical Infrastructure Attacks

Related: Google, FBI Disrupt NetNut Residential Proxy Network Powered by Millions of Devices

Related: 15,000 WordPress Websites Cleaned Up in SocGholish Botnet Takedown

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.securityweek.com/nightmarestresser-ddos-service-disrupted-in-international-operation/