Back to Feed
Threat IntelligenceSep 17, 2026

US takes down NightmareStresser DDoS-for-hire platform

US FBI seizes domains of NightmareStresser, a long-running DDoS-for-hire platform.

Summary

The FBI has seized the domains nightmare-stresser[.]com and nightmarestresser[.]org, operated by NightmareStresser, a prominent DDoS-for-hire service. This platform, active since at least 2022, had over 566,000 registered users and was used to launch hundreds of thousands of attacks. The action is part of Operation PowerOFF, an international law enforcement effort targeting DDoS-for-hire infrastructures.

Full text

US takes down NightmareStresser DDoS-for-hire platform By Sergiu Gatlan September 17, 2026 07:33 AM 0 On Tuesday, the U.S. Federal Bureau of Investigation (FBI) seized the domains used by NightmareStresser, one of the world's longest-running distributed denial-of-service (DDoS) platforms. "Booter services" like NightmareStresser are DDoS-for-hire services that let anyone rent large botnets of compromised routers and a wide range of IoT devices to launch massive DDoS attacks targeting online platforms and services. Before the nightmare-stresser[.]com and nightmarestresser[.]org were taken down, the stresser service described itself as the "#1 online IP booter" and "the only DDoS tool available 24/7." As cybersecurity firm Searchlight Cyber reported in 2023, NightmareStresser had over 566,000 registered users and 52 dedicated servers that could launch DDoS attacks of up to 200 Gbps targeting multiple layers of a network (including Layer 7 application protocols and Layer 4 TCP/UDP protocols). "Since 2022, the NightmareStresser Booter service was used to launch hundreds of thousands of actual or attempted DDoS attacks targeting victims worldwide," the FBI Cyber Division said on Wednesday. "This enforcement action was supported by Operation PowerOFF, a coordinated effort among international law enforcement agencies aimed at dismantling criminal D DoS-for-hire infrastructures worldwide," a seizure banner now displayed on the seized domains reads. NightmareStresser seizure banner (BleepingComputer) In December 2022, the U.S. Department of Justice (DOJ) also took down the nightmarestresser[.]com domain and arrested six suspects who allegedly owned multiple DDoS-for-hire services. Operation ​PowerOFF is an ongoing, long-running joint law enforcement action that began in December 2018 with the seizure of 15 websites linked to DDoS-as-a-service platforms. Previously, this operation has led to the takedown of the DigitalStress DDoS-for-hire service in the United Kingdom, the seizure of the Dstat.cc DDoS review platform, and the arrest of two stresser service operators in Poland. In other joint actions under Operation PowerOFF, law enforcement seized 13 domains and 48 more domains hosting booter platforms in two separate enforcement waves. Last year, Polish authorities also detained four suspects linked to six DDoS-for-hire platforms behind thousands of attacks targeting schools, government services, businesses, and gaming platforms worldwide since 2022, while the U.S. seized nine domains in the same coordinated crackdown on DDoS services. Build your security blueprint for AI-powered attacks Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed. Save your seat Related Articles: Massive DDoS attack disrupts Norway’s government digital servicesUS charges Iranian hackers over $3.4 billion intellectual property theftCISA: Medusa ransomware hit over 500 critical infrastructure orgsFBI: Hackers target online accounts to steal nude photosDDoS attacks over 1 Tbps surged fivefold in the second quarter

Indicators of Compromise

  • domain — nightmare-stresser.com
  • domain — nightmarestresser.org

Entities

NightmareStresser (threat_actor)FBI (vendor)US Department of Justice (vendor)Operation PowerOFF (campaign)