The FBI has seized two domains connected to NightmareStresser, a major DDoS-for-hire platform. Authorities say customers used the service in hundreds of thousands of attacks against targets worldwide.

FBI Seizes NightmareStresser Domains

The FBI seized the domains nightmare-stresser.com and nightmarestresser.org on Tuesday. The sites supported one of the world’s longest-running distributed denial-of-service platforms.

Before the NightmareStresser takedown, the platform promoted itself as a leading IP booter that operated around the clock.

Booter and stresser platforms allow customers to rent access to networks of compromised devices. These botnets often contain hijacked routers and other Internet of Things equipment.

Customers can then direct enormous amounts of traffic toward a website, server or online service. This traffic can overwhelm the target and prevent legitimate users from accessing it.

Such services sometimes claim that customers should use them only for authorised network testing. However, criminals regularly rely on them to disrupt organisations and extort victims.

Service Had More Than 566,000 Users

Cybersecurity company Searchlight Cyber reported in 2023 that NightmareStresser had more than 566,000 registered users.

The platform also operated 52 dedicated servers. According to the researchers, its infrastructure could generate attacks reaching 200 gigabits per second.

Moreover, NightmareStresser could target several network layers. It supported attacks against Layer 7 application protocols as well as Layer 4 TCP and UDP protocols.

This flexibility allowed customers to attack websites, applications and core network services. Attackers could also direct the platform against several targets at the same time.

According to the FBI Cyber Division, users launched hundreds of thousands of attempted or successful DDoS attacks through the platform since 2022. The attacks affected victims around the world.

Operation PowerOFF Supports the Takedown

The FBI conducted the NightmareStresser takedown with support from Operation PowerOFF.

This international law enforcement initiative targets criminal DDoS-for-hire infrastructure. A seizure notice now appears on the confiscated NightmareStresser domains.

Operation PowerOFF brings together agencies from several countries. They coordinate investigations, domain seizures and arrests involving booter and stresser platforms.

The initiative began in December 2018. During its first major action, authorities seized 15 websites that offered DDoS attack services.

Since then, the operation has continued to disrupt platforms that make large-scale cyberattacks available to customers with little technical knowledge.

Authorities Previously Targeted NightmareStresser

The latest action does not mark the first US attempt to shut down NightmareStresser.

In December 2022, the Department of Justice seized the nightmare-stresser.com domain. Authorities also arrested six suspects who allegedly operated several DDoS-for-hire platforms.

However, NightmareStresser later returned and continued providing attack services. The platform’s survival highlights the difficulty of permanently dismantling criminal online infrastructure.

Operators can register replacement domains, move servers or rebuild their services under new names. Therefore, authorities often need to target both the technical infrastructure and the people running it.

International Crackdown Has Closed Other Platforms

Operation PowerOFF has disrupted several other prominent DDoS services in recent years.

For example, British authorities infiltrated and dismantled the DigitalStress attack platform. German investigators also seized Dstat.cc, a website that reviewed and ranked DDoS-for-hire services.

Meanwhile, Polish authorities arrested two people accused of operating a stresser service active since 2013.

US agencies have also conducted several large domain-seizure campaigns. In two separate enforcement waves, authorities confiscated 13 domains and another 48 domains connected to booter platforms.

In 2025, Polish authorities detained four suspects linked to six DDoS-for-hire services. Investigators connected those platforms to thousands of attacks since 2022.

The services targeted schools, government systems, businesses and gaming platforms worldwide. As part of the same coordinated crackdown, US authorities seized nine additional domains.

DDoS Services Lower the Barrier to Cybercrime

DDoS-for-hire platforms allow customers to launch disruptive attacks without building their own botnets. In many cases, users simply select a target, attack method and duration through a web interface.

Consequently, these services make powerful cyberattacks accessible to people with limited technical expertise.

The NightmareStresser takedown removes a major platform from this criminal market. However, its previous return shows that continued international cooperation remains necessary to disrupt replacement services and identify their operators.


0 responses to “FBI Takes Down NightmareStresser DDoS-for-Hire Platform”