№260|07:32 PM ET
Independent reporting on technology, markets & policy
TechEchelon
№01 / Anchor·CYBERSECURITY

FBI Seizes NightmareStresser DDoS-for-Hire Platform Linked to Hundreds of Thousands of Attacks

The FBI seized the domains of NightmareStresser, a long-running DDoS-for-hire platform with over 566,000 registered users, as part of Operation PowerOFF, an international effort to dismantle criminal distributed denial-of-service infrastructure.

TE
TechEchelon Staff
SEP 17, 2026 · 09:02 AM ET · 2 MIN READ
Photo by Jake Walker on Unsplash

The U.S. Federal Bureau of Investigation seized the domains of NightmareStresser on Tuesday, dismantling one of the world's longest-running distributed denial-of-service-for-hire platforms as part of an international law enforcement operation targeting criminal DDoS infrastructure.

The takedown, first reported by BleepingComputer, targeted two domains — nightmare-stresser[.]com and nightmarestresser[.]org — which now display a seizure banner referencing Operation PowerOFF, a coordinated multinational effort to dismantle DDoS-for-hire services worldwide.

"Since 2022, the NightmareStresser Booter service was used to launch hundreds of thousands of actual or attempted DDoS attacks targeting victims worldwide," the FBI Cyber Division said on Wednesday.

Before the seizure, NightmareStresser described itself as the "#1 online IP booter" and "the only DDoS tool available 24/7." Platforms of its type — commonly called "booter" or "stresser" services — allow customers to rent access to botnets composed of compromised routers and Internet of Things devices in order to direct traffic floods at targeted websites and online services.

According to research published by cybersecurity firm Searchlight Cyber in 2023, NightmareStresser had accumulated more than 566,000 registered users and operated 52 dedicated servers capable of generating attacks of up to 200 Gbps. The platform could target multiple network layers simultaneously, including Layer 7 application protocols and Layer 4 TCP/UDP protocols.

This is not the first time U.S. authorities have moved against the service. In December 2022, the Department of Justice took down the nightmarestresser[.]com domain and arrested six suspects allegedly connected to multiple DDoS-for-hire operations — underscoring the difficulty of permanently dismantling services that can reconstitute under new infrastructure.

The current seizure is part of Operation PowerOFF, which dates to December 2018 when law enforcement agencies seized 15 websites linked to DDoS-as-a-service platforms. The operation has since resulted in a string of enforcement actions across multiple jurisdictions.

Prior actions under the operation include the takedown of the DigitalStress DDoS-for-hire service in the United Kingdom, the seizure of the Dstat.cc DDoS review platform, and the arrest of two stresser service operators in Poland. In two separate enforcement waves, law enforcement also seized 13 domains and then 48 more domains hosting booter platforms.

Last year, Polish authorities detained four suspects linked to six DDoS-for-hire platforms responsible for thousands of attacks against schools, government services, businesses, and gaming platforms since 2022. The U.S. seized nine domains in that same coordinated crackdown.

Wednesday's action signals that Operation PowerOFF continues to broaden its scope, with authorities targeting both the infrastructure and the administrators behind services that commoditize cyberattacks — a dynamic that law enforcement officials say shows no sign of abating.

TE
━ ABOUT THE BYLINE
TechEchelon Staff

TechEchelon Staff bylines are produced collectively by the newsroom for short, breaking, and wire-style coverage. Longer-form reporting is published under the responsible reporter's name.

More from the Staff
● THE BRIEF · DAILY NEWSLETTER

Five stories every morning. Before the opening bell.

Written for readers who already know the basics — markets, AI, and the policy decisions that shape both.

Mon — Fri · 06:30 ET · Free

No spam · Unsubscribe anytime