Back to Feed
Threat IntelligenceSep 17, 2026

U.S. Seizes NightmareStresser Domains Linked to Hundreds of Thousands of DDoS Attacks

US seizes NightmareStresser domains used for hundreds of thousands of DDoS attacks.

Summary

The U.S. Department of Justice announced the seizure of domains associated with the DDoS-for-hire service NightmareStresser. This service, which claimed to offer stress testing but was used for malicious attacks, facilitated hundreds of thousands of DDoS attacks globally since 2022. The operation, part of a larger international law enforcement effort, targeted domains used by the service, which had a large user base and offered various attack methods.

Full text

U.S. Seizes NightmareStresser Domains Linked to Hundreds of Thousands of DDoS Attacks Ravie LakshmananSep 17, 2026Cybercrime / DDoS-for-Hire The U.S. Department of Justice (DoJ) on Tuesday announced the court-authorized seizure of internet domains associated with a distributed denial-of-service (DDoS)-for-hire service known as NightmareStresser. The domains in question are: nightmare-stresser[.]com and nightmarestresser[.]org. Visitors to the site are now greeted by a seizure banner that states - "This domain has been seized by the Federal Bureau of Investigation in accordance with a seizure warrant pursuant to 18 U.S.C. §§ 981(a)(1)(A) and (b), 982(b)(1), and 1030(i) (1)(A); and 21 U.S.C. § 853 issued by the United States District Court for the District of Alaska as part of a joint international law enforcement operation and action by: United States Attorney's Office for the District of Alaska, Federal Bureau of Investigation (FBI) Anchorage Field Office, [and] Royal Canadian Mounted Police (RCMP)." These so-called booter services are usually advertised as stress testing utilities but have been used to facilitate attacks targeting a broad range of victims in the U.S. and elsewhere, the Justice Department said. Some of the targeted sectors included educational institutions, government agencies, gaming platforms, and millions of people. "In addition to affecting targeted victims, these attacks can significantly degrade internet services and can completely disrupt internet connections," the DoJ said in a statement. NightmareStresser is assessed to have been used to launch hundreds of thousands of actual or attempted DDoS attacks against victims across the world since 2022. Snapshots captured by the Internet Archive show that the "nightmarestresser[.]org" domain was secured against DDoS attacks by a web infrastructure provider named BlazingFast. In a late 2023 report, Searchlight Cyber said NightmareStresser had more than 566,000 registered users and and 52 servers, stating the panel allows the attacker to choose the IP address or URL to be targeted as well as the port number, along with options to select the number of concurrent attacks. On its now-taken-down website, NightmareStresser claimed to be the "only DDoS tool available 24x7, running non-stop for over 8 years." Ironically, the site also proclaimed, "For over 8 relentless years, NightmareStresser hasn't gone down. Not once. No vanishing acts. No broken promises. Just raw, consistent dominance day and night." Furthermore, NightmareStresser allowed customers to pay in cryptocurrency and featured an "advanced referral system" that allowed users to receive credit when their referral link is used by some other party to visit the website, regardless of whether any purchases were made immediately or later. "Referred users are permanently linked to your account, meaning you earn credit for every renewal or purchase they make over time," the website stated. Services offered by the platform included advanced Layer 4 amplification methods and various bypasses at Layer 4 over UDP/TCP and Layer 7, claiming they can defeat CAPTCHAs, geoblocks, and rate limits. Another feature advertised on its website is a "Stop All" control button that the operators said can be used to stop all Layer 4 or Layer 7 floods. "No matter how many active floods are running whether on Layer 4 or Layer 7 or both, one click is all it takes to halt them instantly," a web page advertising NightmareStresser's features read. "No searching, no delays, no confusion. Just one button exactly when you need it." The takedown is part of a long-running effort called Operation PowerOFF, a coordinated law enforcement initiative that's aimed at dismantling criminal DDoS-for-hire infrastructures globally. In December 2022, another domain linked to NightmareStresser ("nightmarestresser[.]com") was among the 48 domains that were seized by the DoJ. Earlier this April, a similar operation led to the disruption of 53 domains and the arrest of four people in connection with various commercial distributed denial-of-service (DDoS) services that were used by over 75,000 cybercriminals. In all, these law enforcement actions have charged twelve defendants who facilitated DDoS-for-hire services and seized more than 100 internet domains linked to them. "The multi-prong investigation announced today builds on the success of the prior cases by targeting all known booter sites, shutting down as many as possible, and undertaking a public education campaign," the DoJ said. Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post. SHARE     Tweet Share Share Share SHARE  Cybercrime, ddos, DDoS-For-Hire, law enforcement ⚡ Top Stories This Week OpenAI Agents Linked to RubyGems Campaign That Gained RCE on RubyDoc Servers GitLab CVSS 10 File-Read Flaw Draws In-the-Wild Probes After Disclosure Claude Used to Automate Exploitation and Data Theft Across Multiple Victims Attackers Chain JFrog Artifactory Flaws to Gain Admin Control and Plant Backdoors PaperCut Replaces Emergency Patches With Fixes for Two Actively Exploited Flaws Cisco FMC Flaws Exploited to Steal Credentials and Deploy Qilin Ransomware ThreatsDay: 200 Android Flaws, Browser-Built Phishing, 119K Scam Shops + 23 More Stories Check Point Discloses Two 9.8-Rated VPN Certificate Flaws Enabling Unauthenticated RCE Anthropic Discloses Fourth AI Hacking Incident Involving Claude Opus 4.6 Four Spy Groups Used the Same Chrome and Windows Exploit Kit Within a Week DeepSeek Harness Flaw Let AI Agents Disable Their Own File Sandbox Without Approval Chrome V8 Zero-Day Exploited in the Wild Enables Code Execution Inside Sandbox New cPanel Flaw Lets a Hosting Account With Mail Privileges Run Code as Root F5 BIG-IP APM Malware Injects a PHP Web Shell Into Memory, Evading Disk Scans Researcher Drops New Microsoft Defender PoC Showing ShieldBreak Patch Can Be Bypassed Microsoft Patches Record 974 Flaws, Including Two Exploited Windows Zero-Days ChatGPT Flaw Let a Planted Prompt Send a Victim's Gmail Data to Another Account WeChat Zero-Click Worm Took Over Accounts on iPhone and Android via Incoming Calls Fake IT Calls Target Executives in Microsoft 365 Data Theft and Extortion Attacks When the Whole Company Adopts AI: What It Does to Your SOC Your Critical Vulnerabilities Might Not Be Your Biggest Risk What It Took to Reach 1 Billion Build Manifests US Becomes Top Target in RMM Phishing Campaign Spanning 46 Countries Why Are So Many Security Professionals Keeping Breaches Quiet? The Economics of Dwell Time and Why AI Native SIEM Changes the Equation ⭐ Featured Resources Get the eBook: Map Enterprise AI Risk Across the Full Lifecycle Give SOC Analysts Visibility Into 90% of Attacks Within 60 Seconds Benchmark Your SOC's AI Adoption With the 2026 Security Operations Report Register for LDR516: Strategic Vulnerability and Threat Management at SANS DC Metro

Indicators of Compromise

  • domain — nightmare-stresser[.]com
  • domain — nightmarestresser[.]org

Entities

NightmareStresser (threat_actor)NightmareStresser (product)BlazingFast (vendor)