FBI Domain Seizures Cut Off NightmareStresser’s DDoS-for-Hire Storefront

FBI seized NightmareStresser domains in Operation PowerOFF, disrupting a DDoS-for-hire service linked to hundreds of thousands of attacks.

Text generated by artificial intelligence, published without human review. AI transparency

FBI Domain Seizures Cut Off NightmareStresser’s DDoS-for-Hire Storefront
Malware

Illustrative image generated with AI

Listen to this articleAudio edition · 9 min

The FBI has seized two domains used by NightmareStresser, a commercial distributed denial-of-service platform accused of enabling hundreds of thousands of attacks worldwide. The action forms part of Operation PowerOFF, an international campaign against services that sell disruptive attack capacity to paying customers.

The disruption was reported on September 18, 2026. The precise date on which the domains were seized has not been disclosed.

Both nightmare-stresser[.]com and nightmarestresser[.]org now display an official seizure notice. The intervention removes NightmareStresser’s identified public-facing websites from normal operation, but it does not establish that every backend server, payment record, customer account or attack system has been neutralized.

A Paid Platform Built to Industrialize DDoS Attacks

NightmareStresser operated as a “booter” or “stresser,” terms commonly used for services that let customers purchase distributed denial-of-service attacks. Although stress-testing tools can have legitimate uses when operated with authorization, commercial booter platforms enable customers to direct traffic against third-party systems.

This model lowers the barrier to disruptive cybercrime. Users do not need to assemble a botnet, develop attack software or independently manage distributed infrastructure. They can instead buy capacity and specify a target through a service interface.

NightmareStresser accepted cryptocurrency payments, allowing customers to avoid conventional payment channels. The available information does not identify the supported cryptocurrencies, pricing structure, subscription tiers or payment addresses.

Authorities allege that the platform was used for hundreds of thousands of attacks against victims around the world. By 2025, it reportedly had nearly one million users and could generate between 3,000 and 4,000 attacks per hour.

Those figures describe the platform’s scale rather than the characteristics of each incident. No details have been disclosed about attack duration, bandwidth, packet rates, amplification techniques or application-layer methods.

Years of Growth Before the Takedown

Authorities say NightmareStresser had been active since at least 2022. Security researcher Alex Carter presented a longer history last year, assessing that the service was probably established in 2016.

According to Carter’s account, NightmareStresser gained substantial popularity in 2018 after competing services were disrupted. It then became the largest DDoS tool in 2019.

That trajectory illustrates a persistent problem with takedowns: demand can shift from a disrupted platform to surviving competitors. Operators can also attempt to rebuild under new names, domains or administrative infrastructure.

NightmareStresser reportedly prevented customers from targeting government, educational and hospital domains. It is not known how those exclusions were implemented, whether through domain blocklists or another control, or how consistently they were enforced. The restrictions would not make attacks against other organizations lawful.

Operation PowerOFF Targets Operators and Customers

The NightmareStresser enforcement action was conducted through Operation PowerOFF, which coordinates international investigations into DDoS-for-hire platforms and the people behind them.

The FBI took control of the two identified domains, while the US Department of Justice announced the disruption. No arrests, charges or named suspects connected specifically to NightmareStresser have been disclosed.

Investigators are not limiting their attention to service administrators. Operation PowerOFF also targets customers and other users who order or carry out attacks through booter platforms. Purchasing access does not insulate a customer from investigation simply because someone else maintains the underlying infrastructure.

The broader campaign has produced repeated enforcement actions:

  • Over the past eight years, US authorities have charged 12 people accused of facilitating DDoS attacks.
  • More than 100 domains associated with booter services have been seized by US authorities.
  • In April, agencies from 21 countries disrupted 53 domains linked to DDoS-for-hire operations.
  • Twenty-seven booter-related websites were seized in 2024.
  • The United States disrupted the RapperBot DDoS botnet last year.

These actions combine infrastructure seizures with investigations and prosecutions. However, the removal of individual platforms has not eliminated the wider market.

Domain Control Does Not Prove the Attack Network Is Gone

A domain seizure can immediately interfere with customer access, new registrations and web-based administration. It can also provide investigators with opportunities to collect evidence, depending on the systems and records placed under their control.

Its effect has limits. The public information does not confirm whether law enforcement obtained NightmareStresser’s backend servers, source code, cryptocurrency wallets, subscriber database or attack infrastructure. It is also unknown whether operators retained alternative domains or communication channels.

Consequently, the seizure banner should not be interpreted as proof that all NightmareStresser-linked activity has stopped. Operators could attempt to restore the service elsewhere, while existing customers may migrate to another provider.

No IP addresses, malware hashes, account identifiers, payment addresses or network signatures have been released. There are therefore no specific technical indicators that defenders can use to attribute traffic conclusively to NightmareStresser.

The two seized domains may still be useful when reviewing historical DNS, proxy and email records. A match would show some form of interaction, but it would not by itself prove that a user purchased or launched an attack.

The Damage Is Primarily to Availability

NightmareStresser represents an availability threat rather than a disclosed data-theft or endpoint-compromise campaign. Its purpose was to direct enough malicious traffic at a target to degrade or deny access to online services.

Potential consequences include website and API outages, unstable customer-facing applications, higher bandwidth or mitigation costs, and additional pressure on infrastructure and incident-response teams. Organizations dependent on online transactions can also experience operational and financial disruption while an attack remains active.

No specific victim organizations have been identified. It is also not known whether any incidents caused prolonged outages or whether targets suffered secondary security events.

There is no software vulnerability associated with this case. No CVE identifiers, affected product versions or patches are involved, and the action is not related to CISA’s Known Exploited Vulnerabilities catalog.

What Defenders Should Do After the Disruption

Organizations should use the takedown to review both past incidents and current DDoS readiness. The absence of public technical indicators makes behavioral and infrastructure-level analysis particularly important.

Defensive teams can take several practical steps:

  • Review historical network, DNS, application and provider telemetry for contacts involving nightmare-stresser[.]com or nightmarestresser[.]org.
  • Preserve logs from unexplained DDoS incidents in case law enforcement or service providers later release additional indicators.
  • Confirm escalation procedures with hosting companies, internet providers, content-delivery networks and DDoS mitigation vendors.
  • Test rate limits, traffic filters, failover mechanisms and business-continuity plans under realistic load conditions.
  • Monitor newly registered domains and other channels for credible signs that NightmareStresser has returned under different infrastructure.
  • Report suspected booter activity and related extortion or disruption attempts to the appropriate authorities and providers.

Attribution should remain cautious. Similar traffic patterns can be generated by many DDoS services, botnets and independent attackers.

The seizures have removed NightmareStresser’s known web properties and interrupted an operation with a substantial reported customer base. Whether that interruption becomes permanent will depend on what infrastructure and evidence investigators obtained beyond the two domains.

Read next

Sources

This article is an original reworking based on the sources below.

Related topicsNightmareStresserFBI domain seizureDDoS-for-hireOperation PowerOFFbooter servicecybercrime takedown
Back to home