Back to Feed
Threat IntelligenceSep 18, 2026

NightmareStresser DDoS Service Disrupted in International Operation

NightmareStresser, a long-running DDoS-for-hire service, has been disrupted by international law enforcement.

Summary

The FBI, as part of Operation PowerOFF, has seized domains associated with NightmareStresser, a DDoS-for-hire service active since at least 2022. This global effort aims to dismantle DDoS-for-hire infrastructures and hold their operators accountable. NightmareStresser was capable of launching thousands of attacks per hour and accepted cryptocurrency payments.

Full text

NightmareStresser, one of the longest-running distributed denial-of-service (DDoS) for-hire services in the world, has been disrupted. The US Department of Justice announced this week that the FBI has seized the internet domains associated with the booter service. Visitors to nightmare-stresser[.]com and nightmarestresser[.]org are now served a seizure banner. Authorities said NightmareStresser had been active since at least 2022 and was used to launch hundreds of thousands of DDoS attacks against victims worldwide. However, security researcher Alex Carter reported last year that NightmareStresser was likely founded in 2016 and became popular in 2018, after rival services were disrupted, becoming the largest DDoS tool in 2019. By 2025, it had grown to nearly 1 million users. It could launch between 3,000 and 4,000 attacks per hour, accepted cryptocurrency payments, but avoided government, education, and hospital domains.Advertisement. Scroll to continue reading. The NightmareStresser takedown was part of Operation PowerOFF, a coordinated global effort to dismantle DDoS-for-hire infrastructures globally and hold the individuals behind these services accountable. DDoS-for-hire services, also referred to as booters or stressers, have been proliferating over the past years, as they represent low-entry barriers for cybercriminal-wannabes, the DoJ notes. Over the past eight years, the US charged 12 DDoS attack facilitators and seized over 100 domains associated with booter services. In April, law enforcement agencies in 21 countries disrupted 53 domains associated with DDoS-for-hire services. Last year, the US disrupted the RapperBot DDoS botnet, and 27 websites linked to booter services were seized in 2024. In addition to disrupting DDoS-for-hire infrastructure, law enforcement agencies have been tracking and charging both the administrators and the users of these services. Related: 23-Year-Old Sality P2P Botnet Disrupted Related: US Disrupts Chinese Hacking Platform Used in Military and Critical Infrastructure Attacks Related: Google, FBI Disrupt NetNut Residential Proxy Network Powered by Millions of Devices Related: 15,000 WordPress Websites Cleaned Up in SocGholish Botnet Takedown Written By Ionut Arghire Ionut Arghire is an international correspondent for SecurityWeek. Daily Briefing Newsletter Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights. More from Ionut Arghire Revolut Data Breach: 5 Months, 680 High-Profile Accounts, $3M RansomComp AI Raises $34 Million for AI-Native Compliance and SecurityISC Patches 14 Vulnerabilities in BIND 9 Security UpdateCisco Fixes Dozens of Flaws Across FMC, ISE and Nexus DashboardCISA Releases Cyber Decoy Guidance to Strengthen Critical Infrastructure DefensesActive Exploitation Triggers Emergency Patch for Cisco ISE Zero-DayAIUC Raises $40 Million to Certify Enterprise AI AgentsUnauthenticated RCE Flaws Could Expose 200,000+ WordPress Sites to Takeover Latest News 23 Million User Records Compromised in Gyazo Data Breach Microsoft Patches 18 Vulnerabilities in AI, Cloud ProductsBrevo Supply Chain Attack Injects Malware Into 100,000 WebsitesCritical Orkes Conductor Vulnerability Exploited in AttacksMIND Secures $72 Million for AI-Powered DLPCheck Point, Kaspersky, Tanium Patch Product VulnerabilitiesCyberattacks on Two Oil Tankers Prompt Coast Guard, FBI to Board VesselsOpenAI Says Its Models Searched GitHub for Leaked API Keys During Training Trending Daily Briefing NewsletterSubscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts. Virtual Event: Attack Surface Management Summit 2026 September 16, 2026 Join as speakers examine the various components of ASM strategy, the push to mandate continuous asset visibility and inventory tools, and the use of red-teaming, bug bounties and pen-tests in modern security programs. Register Webinar: Building Continuous Authorization at Scale September 23, 2026 Explore what it takes to operationalize continuous authorization at scale, including the technical, organizational, and cultural changes required. Register People on the MoveVeritas Capital has appointed Joel Fulton as Chief Information Security Officer.incident.io has appointed Carlos Gonzalez-Cadenas as Chief Operating Officer.Ruben D. Chacon has joined ADM as Vice President and Global CISO.More People On The MoveExpert Insights “We Think the Security Control Is Working” Is No Longer Good Enough Point-in-time audits and sampled assessments offer only snapshots; continuous control monitoring provides evidence that security controls are working today. (Sravish Sridhar) This Key Will Self-Destruct: An Open Standard for Revocable API Keys Every leaked credential should be dead, or dying, within sixty seconds of being found. Here's a proposal to make that the default. (Matt Honea) What the Hugging Face Incident Teaches Security Leaders About AI Agent Access Security teams must treat autonomous agents as highly privileged identities. (Etay Maor) The Future of AI-Driven Security Depends on Complete Data For twenty-five years, "data" in security meant logs and events. But logs are a lossy representation of reality. (Danelle Au) The MFA Identity Trap: When Authentication Creates a False Sense of Security Organizations must distinguish identity verification, authentication and threat detection, or risk successfully authenticating the attackers they are trying to stop. (Torsten George) Flipboard Reddit Whatsapp Whatsapp Email

Indicators of Compromise

  • domain — nightmare-stresser[.]com
  • domain — nightmarestresser[.]org

Entities

NightmareStresser (threat_actor)Operation PowerOFF (campaign)