INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
DDoS-for-hire Service Seized by US Authorities
| 2026-09-17 13:37 MEDIUM MEDIUM DDOS & DISRUPTION LAW ENFORCEMENT
Executive Summary
AI-generated
Law enforcement officials have taken down the NightmareStresser DDoS-for-hire platform, a notorious threat actor's operation that has been targeting various victims worldwide since at least 2022. The seizure of the primary domain and other websites linked to the service marks an ongoing effort by authorities to disrupt cybercriminals' activities. This takedown is part of "Operation PowerOFF," a globally coordinated effort aimed at bringing down IP stressers or DDoS booters that inundate websites, servers, and networks with junk traffic, rendering legitimate sites inaccessible. The successful takedown demonstrates the effectiveness of law enforcement's efforts in targeting these threat actors and brings hope to those whose services have been disrupted.
Technical Mitigations AI-generated
* Implement robust security measures, such as encryption and secure authentication protocols, to protect against DDoS-for-hire services like NightmareStresser.
* Regularly update and patch software and systems to prevent exploitation of known vulnerabilities by threat actors targeting these platforms.
* Conduct thorough risk assessments and vulnerability scans for potential targets before engaging in online activities or hosting sensitive information.
* Utilize secure communication protocols, such as HTTPS and SFTP, when transferring data or storing sensitive information online.
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected
Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.
ni•••••.com
ni•••••.com
ni•••••.org
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Operation PowerOFFOperation PowerOFF
Target & Sectors
NORTH_AMERICA
NORTH_AMERICA
governmentgovernment
Incident Timeline
December 2018
The authorities seized 15 DDoS-for-hire service domains in December 2018 as part of the ongoing Operation PowerOFF joint law enforcement action.
Click on any entity below to view its context and source!
tactic
Ddos
Operation PowerOFF is an ongoing, long-running joint law enforcement action that began in December 2018 with the seizure of
15 websites linked to DDoS-as-a-service platforms
.
organisation
Operation PowerOFF
Operation PowerOFF is an ongoing, long-running joint law enforcement action that began in December 2018 with the seizure of
15 websites linked to DDoS-as-a-service platforms
.
general_metric
15 websites
Operation PowerOFF is an ongoing, long-running joint law enforcement action that began in December 2018 with the seizure of
15 websites linked to DDoS-as-a-service platforms
.
December 2022
The U.S. Department of Justice seized the nightmarestresser[.]com domain and arrested six suspects linked to a popular DDoS-for-hire service.
Click on any entity below to view its context and source!
tactic
Ddos
NightmareStresser seizure banner (BleepingComputer)
In December 2022, the U.S. Department of Justice (DOJ)
also took down the nightmarestresser[.]com domain
and arrested six suspects who allegedly owned multiple DDoS-for-hire services.
In December 2022, another domain linked to NightmareStresser ("nightmarestresser[.]com") was
among the 48 domains
that were seized by the DoJ.
Earlier this April, a similar operation led to the disruption of 53 domains and the arrest of four people in connection with various commercial distributed denial-of-service (DDoS) services that were used by over 75,000 cybercriminals.
organisation
the U.S. Department of Justice
NightmareStresser seizure banner (BleepingComputer)
In December 2022, the U.S. Department of Justice (DOJ)
also took down the nightmarestresser[.]com domain
and arrested six suspects who allegedly owned multiple DDoS-for-hire services.
organisation
nightmarestresser[.]com
NightmareStresser seizure banner (BleepingComputer)
In December 2022, the U.S. Department of Justice (DOJ)
also took down the nightmarestresser[.]com domain
and arrested six suspects who allegedly owned multiple DDoS-for-hire services.
infrastructure
48 domains
In December 2022, another domain linked to NightmareStresser ("nightmarestresser[.]com") was
among the 48 domains
that were seized by the DoJ.
Earlier this April, a similar operation led to the disruption of 53 domains and the arrest of four people in connection with various commercial distributed denial-of-service (DDoS) services that were used by over 75,000 cybercriminals.
infrastructure
53 domains
In December 2022, another domain linked to NightmareStresser ("nightmarestresser[.]com") was
among the 48 domains
that were seized by the DoJ.
Earlier this April, a similar operation led to the disruption of 53 domains and the arrest of four people in connection with various commercial distributed denial-of-service (DDoS) services that were used by over 75,000 cybercriminals.
general_metric
75,000 cybercriminals
In December 2022, another domain linked to NightmareStresser ("nightmarestresser[.]com") was
among the 48 domains
that were seized by the DoJ.
Earlier this April, a similar operation led to the disruption of 53 domains and the arrest of four people in connection with various commercial distributed denial-of-service (DDoS) services that were used by over 75,000 cybercriminals.
2025/09/17
Polish authorities seized domains linked to DDoS-for-hire service.
Click on any entity below to view its context and source!
industry
Government
Last year, Polish authorities
also detained four suspects
linked to six DDoS-for-hire platforms behind thousands of attacks targeting schools, government services, businesses, and gaming platforms worldwide since 2022, while the U.S.
seized nine domains
in the same coordinated crackdown on DDoS services.
tactic
Ddos
Last year, Polish authorities
also detained four suspects
linked to six DDoS-for-hire platforms behind thousands of attacks targeting schools, government services, businesses, and gaming platforms worldwide since 2022, while the U.S.
seized nine domains
in the same coordinated crackdown on DDoS services.
source_region
Poland
Last year, Polish authorities
also detained four suspects
linked to six DDoS-for-hire platforms behind thousands of attacks targeting schools, government services, businesses, and gaming platforms worldwide since 2022, while the U.S.
seized nine domains
in the same coordinated crackdown on DDoS services.
2026/09/17
The US Department of Justice seized and shut down multiple domains associated with a popular DDoS-for-hire service.
Click on any entity below to view its context and source!
industry
Education
"The multi-prong investigation announced today builds on the success of the prior cases by targeting all known booter sites, shutting down as many as possible, and undertaking a public education campaign," the DoJ said.
Sep 17, 2026
The authorities seized domains associated with a popular DDoS-for-hire service.
2026/09/17
The US Federal Bureau of Investigation (FBI) seized the primary domain and other websites linked to NightmareStresser, a popular DDoS-for-hire service.
Click on any entity below to view its context and source!
organisation
NightmareStresser
Officials didn’t name the operators of NightmareStresser or identify its country of origin, but the service claimed it operated under the laws of Russia, Zach Edwards, staff threat researcher at Infoblox told CyberScoop.
US takes down NightmareStresser DDoS-for-hire platform.
Ravie Lakshmanan
Sep 17, 2026
Cybercrime / DDoS-for-Hire
The U.S. Department of Justice (DoJ) on Tuesday announced the court-authorized seizure of internet domains associated with a distributed denial-of-service (DDoS)-for-hire service known as NightmareStresser.
organisation
CyberScoop
Officials didn’t name the operators of NightmareStresser or identify its country of origin, but the service claimed it operated under the laws of Russia, Zach Edwards, staff threat researcher at Infoblox told CyberScoop.
organisation
The U.S. Department of Justice (DoJ
Ravie Lakshmanan
Sep 17, 2026
Cybercrime / DDoS-for-Hire
The U.S. Department of Justice (DoJ) on Tuesday announced the court-authorized seizure of internet domains associated with a distributed denial-of-service (DDoS)-for-hire service known as NightmareStresser.
organisation
IP
The takedown, part of an ongoing globally coordinated effort dubbed “
Operation PowerOFF
,” marks law enforcement’s continued
targeting of IP stressers or DDoS booters
that inundate websites, servers and networks with junk traffic, rendering legitimate sites inaccessible.
Before the nightmare-stresser[.]com and nightmarestresser[.]org were
taken down
, the stresser service
described itself
as the "#1 online IP booter" and "the only DDoS tool available 24/7.
In a late 2023 report, Searchlight Cyber
said
NightmareStresser had more than 566,000 registered users and and 52 servers, stating the panel allows the attacker to choose the IP address or URL to be targeted as well as the port number, along with options to select the number of concurrent attacks.
infrastructure
100 domains
Authorities said they’ve seized more than 100 domains associated with DDoS-for-hire services since 2018.
In all, these law enforcement actions have charged twelve defendants who facilitated DDoS-for-hire services and seized more than 100 internet domains linked to them.
organisation
DDoS
“The vast majority of people who actually use DDoS services like NightmareStresser are script kiddies, oftentimes for pranks or for some sort of obscure political agenda.
"Booter services" like NightmareStresser are DDoS-for-hire services that let anyone rent large botnets of compromised routers and a wide range of IoT devices to launch massive DDoS attacks targeting online platforms and services.
NightmareStresser
is assessed to have been used to launch hundreds of thousands of actual or attempted DDoS attacks against victims across the world since 2022.
organisation
DigitalStress
DDoS
Previously, this operation has led to the takedown of the
DigitalStress
DDoS-for-hire service in the United Kingdom, the seizure of the
Dstat.cc DDoS review platform
, and the arrest of two
stresser service operators
in Poland.
organisation
IoT
"Booter services" like NightmareStresser are DDoS-for-hire services that let anyone rent large botnets of compromised routers and a wide range of IoT devices to launch massive DDoS attacks targeting online platforms and services.
organisation
nightmarestresser[.]org
Before the nightmare-stresser[.]com and nightmarestresser[.]org were
taken down
, the stresser service
described itself
as the "#1 online IP booter" and "the only DDoS tool available 24/7.
The domains in question are: nightmare-stresser[.]com and nightmarestresser[.]org.
financial
1 online IP booter
Before the nightmare-stresser[.]com and nightmarestresser[.]org were
taken down
, the stresser service
described itself
as the "#1 online IP booter" and "the only DDoS tool available 24/7.
organisation
Layer 7
"
As cybersecurity firm Searchlight Cyber
reported in 2023
, NightmareStresser had over 566,000 registered users and 52 dedicated servers that could launch DDoS attacks of up to 200 Gbps targeting multiple layers of a network (including Layer 7 application protocols and Layer 4 TCP/UDP protocols).
Services offered by the platform included advanced Layer 4 amplification methods and various bypasses at Layer 4 over UDP/TCP and Layer 7, claiming they can defeat CAPTCHAs, geoblocks, and rate limits.
victims
566,000 registered users
"
As cybersecurity firm Searchlight Cyber
reported in 2023
, NightmareStresser had over 566,000 registered users and 52 dedicated servers that could launch DDoS attacks of up to 200 Gbps targeting multiple layers of a network (including Layer 7 application protocols and Layer 4 TCP/UDP protocols).
In a late 2023 report, Searchlight Cyber
said
NightmareStresser had more than 566,000 registered users and and 52 servers, stating the panel allows the attacker to choose the IP address or URL to be targeted as well as the port number, along with options to select the number of concurrent attacks.
infrastructure
52 dedicated servers
"
As cybersecurity firm Searchlight Cyber
reported in 2023
, NightmareStresser had over 566,000 registered users and 52 dedicated servers that could launch DDoS attacks of up to 200 Gbps targeting multiple layers of a network (including Layer 7 application protocols and Layer 4 TCP/UDP protocols).
In a late 2023 report, Searchlight Cyber
said
NightmareStresser had more than 566,000 registered users and and 52 servers, stating the panel allows the attacker to choose the IP address or URL to be targeted as well as the port number, along with options to select the number of concurrent attacks.
data_breach
200 Gbps
"
As cybersecurity firm Searchlight Cyber
reported in 2023
, NightmareStresser had over 566,000 registered users and 52 dedicated servers that could launch DDoS attacks of up to 200 Gbps targeting multiple layers of a network (including Layer 7 application protocols and Layer 4 TCP/UDP protocols).
organisation
Operation PowerOFF
In other joint actions under Operation PowerOFF, law enforcement
seized 13 domains
and
48 more domains
hosting booter platforms in two separate enforcement waves.
infrastructure
13 domains
In other joint actions under Operation PowerOFF, law enforcement
seized 13 domains
and
48 more domains
hosting booter platforms in two separate enforcement waves.
infrastructure
48 domains
In other joint actions under Operation PowerOFF, law enforcement
seized 13 domains
and
48 more domains
hosting booter platforms in two separate enforcement waves.
organisation
UDP/TCP
Services offered by the platform included advanced Layer 4 amplification methods and various bypasses at Layer 4 over UDP/TCP and Layer 7, claiming they can defeat CAPTCHAs, geoblocks, and rate limits.
organisation
NFL
Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.
organisation
CHANEL
Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.
organisation
the Justice Department
"
These so-called booter services are usually advertised as stress testing utilities but have been used to facilitate attacks targeting a broad range of victims in the U.S. and elsewhere, the Justice Department said.
organisation
DoJ
"In addition to affecting targeted victims, these attacks can significantly degrade internet services and can completely disrupt internet connections," the DoJ
said
in a statement.
Tactical Metrics
Metrics
infrastructure
100
Domains
Click for context!
Authorities said they’ve seized more than 100 domains associated with DDoS-for-hire services since 2018.
In all, these law enforcement actions have charged twelve defendants who facilitated DDoS-for-hire services and seized more than 100 internet domains linked to them.
Metrics
financial
1
Online Ip Booter
Before the nightmare-stresser[.]com and nightmarestresser[.]org were
taken down
, the stresser service
described itself
as the "#1 online IP booter" and "the only DDoS tool available 24/7.
Metrics
victims
566,000
Registered Users
"
As cybersecurity firm Searchlight Cyber
reported in 2023
, NightmareStresser had over 566,000 registered users and 52 dedicated servers that could launch DDoS attacks of up to 200 Gbps targeting multiple layers of a network (including Layer 7 application protocols and Layer 4 TCP/UDP protocols).
In a late 2023 report, Searchlight Cyber
said
NightmareStresser had more than 566,000 registered users and and 52 servers, stating the panel allows the attacker to choose the IP address or URL to be targeted as well as the port number, along with options to select the number of concurrent attacks.
Metrics
infrastructure
52
Dedicated Servers
"
As cybersecurity firm Searchlight Cyber
reported in 2023
, NightmareStresser had over 566,000 registered users and 52 dedicated servers that could launch DDoS attacks of up to 200 Gbps targeting multiple layers of a network (including Layer 7 application protocols and Layer 4 TCP/UDP protocols).
In a late 2023 report, Searchlight Cyber
said
NightmareStresser had more than 566,000 registered users and and 52 servers, stating the panel allows the attacker to choose the IP address or URL to be targeted as well as the port number, along with options to select the number of concurrent attacks.
Metrics
data_breach
200
Gbps
"
As cybersecurity firm Searchlight Cyber
reported in 2023
, NightmareStresser had over 566,000 registered users and 52 dedicated servers that could launch DDoS attacks of up to 200 Gbps targeting multiple layers of a network (including Layer 7 application protocols and Layer 4 TCP/UDP protocols).
Metrics
infrastructure
13
Domains
In other joint actions under Operation PowerOFF, law enforcement
seized 13 domains
and
48 more domains
hosting booter platforms in two separate enforcement waves.
Metrics
infrastructure
48
Domains
In other joint actions under Operation PowerOFF, law enforcement
seized 13 domains
and
48 more domains
hosting booter platforms in two separate enforcement waves.
In December 2022, another domain linked to NightmareStresser ("nightmarestresser[.]com") was
among the 48 domains
that were seized by the DoJ.
Earlier this April, a similar operation led to the disruption of 53 domains and the arrest of four people in connection with various commercial distributed denial-of-service (DDoS) services that were used by over 75,000 cybercriminals.
Metrics
infrastructure
53
Domains
In December 2022, another domain linked to NightmareStresser ("nightmarestresser[.]com") was
among the 48 domains
that were seized by the DoJ.
Earlier this April, a similar operation led to the disruption of 53 domains and the arrest of four people in connection with various commercial distributed denial-of-service (DDoS) services that were used by over 75,000 cybercriminals.
Intelligence Sources
BleepingComputer
2026-09-17
US takes down NightmareStresser DDoS-for-hire platform
BleepingComputer
The Hacker News
2026-09-17
CyberScoop
2026-09-17
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-09-18T06:01
Comprehensive Tactical Telemetry
Highly Correlated Entities
18x
organisation
Identified Entity
NightmareStresser
entity
12x
attribution
Attributing Entity
NightmareStresser
authority
11x
timeline
Temporal Reference
2018
date
4x
infrastructure
Domains
100
domains
3x
source region
Origin Country
Russian Federation
country
2x
target region
Target Country
United States
country
2x
industry
Targeted Sector
Government
sector
2x
general metric
U.S.C. §
21
u.s.c. §
Contextual Telemetry
Context Block
13 METRICS
tactic
Cyber Operation Type
Ddos
tactic
campaign
Campaign
Operation PowerOFF
operation
financial
Online Ip Booter
1
online ip booter
victims
Registered Users
566,000
registered users
infrastructure
Dedicated Servers
52
dedicated servers
data breach
Gbps
200
gbps
general metric
Application Protocols
7
application protocols
general metric
Layer Udp Protocols
4
layer udp protocols
general metric
Websites
15
websites
tactic
MITRE ATT&CK Technique
T1584.001 - Domains
technique
general metric
Sep
17
sep
general metric
Cybercriminals
75,000
cybercriminals
general metric
Late Report
2,023
late report
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.