U.S. Seizes NightmareStresser Domains Linked to Hundreds of Thousands of DDoS Attacksnew
The U.S. DoJ seized NightmareStresser DDoS-for-hire domains, disrupting a booter service linked to hundreds of thousands of attacks since 2022.
The U.S. Department of Justice announced a court-authorized seizure of nightmare-stresser[.]com and nightmarestresser[.]org, conducted with the FBI Anchorage Field Office and the Royal Canadian Mounted Police as part of Operation PowerOFF. Searchlight Cyber reported in 2023 that NightmareStresser had over 566,000 registered users and 52 servers, offering Layer 4 amplification and Layer 7 floods against education, government, and gaming victims. The seizure follows earlier actions, including 48 domains seized in December 2022 and 53 domains plus four arrests this April, bringing totals to twelve charged defendants and more than 100 seized domains.
Australia charges two men for TeamPCP supply
Australia charged two Perth men over TeamPCP supply-chain attacks compromising 1,000+ organizations and exposing 500,000+ credentials.
The AFP charged two Perth-based men with a combined 14 offences for their alleged roles in TeamPCP, with payments in cryptocurrency for data intrusion, identity crime, and money laundering. The group's supply-chain attacks targeted developer tools including TanStack, Trivy, and LiteLLM, with downstream victims including the European Commission and GitHub. Investigators estimate the campaign compromised over 1,000 organizations, exposed more than 500,000 credentials, and led to theft of at least 300 GB of data, with remediation costs in the hundreds of millions of dollars. The men could face a combined 82 years if given maximum sentences, though sentences are typically served concurrently.