The U.S. Federal Bureau of Investigation seized the domains of NightmareStresser on Tuesday, dismantling one of the world's longest-running distributed denial-of-service-for-hire platforms as part of an international law enforcement operation targeting criminal DDoS infrastructure.
The takedown, first reported by BleepingComputer, targeted two domains — nightmare-stresser[.]com and nightmarestresser[.]org — which now display a seizure banner referencing Operation PowerOFF, a coordinated multinational effort to dismantle DDoS-for-hire services worldwide.
"Since 2022, the NightmareStresser Booter service was used to launch hundreds of thousands of actual or attempted DDoS attacks targeting victims worldwide," the FBI Cyber Division said on Wednesday.
Before the seizure, NightmareStresser described itself as the "#1 online IP booter" and "the only DDoS tool available 24/7." Platforms of its type — commonly called "booter" or "stresser" services — allow customers to rent access to botnets composed of compromised routers and Internet of Things devices in order to direct traffic floods at targeted websites and online services.
According to research published by cybersecurity firm Searchlight Cyber in 2023, NightmareStresser had accumulated more than 566,000 registered users and operated 52 dedicated servers capable of generating attacks of up to 200 Gbps. The platform could target multiple network layers simultaneously, including Layer 7 application protocols and Layer 4 TCP/UDP protocols.
This is not the first time U.S. authorities have moved against the service. In December 2022, the Department of Justice took down the nightmarestresser[.]com domain and arrested six suspects allegedly connected to multiple DDoS-for-hire operations — underscoring the difficulty of permanently dismantling services that can reconstitute under new infrastructure.
The current seizure is part of Operation PowerOFF, which dates to December 2018 when law enforcement agencies seized 15 websites linked to DDoS-as-a-service platforms. The operation has since resulted in a string of enforcement actions across multiple jurisdictions.
Prior actions under the operation include the takedown of the DigitalStress DDoS-for-hire service in the United Kingdom, the seizure of the Dstat.cc DDoS review platform, and the arrest of two stresser service operators in Poland. In two separate enforcement waves, law enforcement also seized 13 domains and then 48 more domains hosting booter platforms.
Last year, Polish authorities detained four suspects linked to six DDoS-for-hire platforms responsible for thousands of attacks against schools, government services, businesses, and gaming platforms since 2022. The U.S. seized nine domains in that same coordinated crackdown.
Wednesday's action signals that Operation PowerOFF continues to broaden its scope, with authorities targeting both the infrastructure and the administrators behind services that commoditize cyberattacks — a dynamic that law enforcement officials say shows no sign of abating.