Skip to main content
The Wire
CyberNews by Zentrya One
Threat Intel

U.S. Seizes NightmareStresser Domains Linked to Hundreds of Thousands of DDoS Attacks

The FBI seized domains linked to NightmareStresser, a major DDoS-for-hire service blamed for hundreds of thousands of actual or attempted attacks worldwide since 2022.

U.S. authorities have disrupted NightmareStresser, one of the world's longest-running distributed denial-of-service (DDoS)-for-hire platforms, seizing domains associated with a service allegedly responsible for hundreds of thousands of attacks and attempted attacks worldwide.

The U.S. Department of Justice (DOJ) announced the court-authorized operation on September 15, 2026, with the Federal Bureau of Investigation (FBI) taking control of domains used by the service.

The operation was conducted with support from the Royal Canadian Mounted Police (RCMP) and forms part of Operation PowerOFF, an ongoing international law-enforcement effort targeting criminal DDoS-for-hire infrastructure.

NightmareStresser at a Glance

Detail Information
Service NightmareStresser
Type DDoS-for-hire / booter / stresser
Domains targeted nightmare-stresser[.]com, nightmarestresser[.]org
Enforcement FBI / U.S. Department of Justice
International Partner Royal Canadian Mounted Police
Operation Operation PowerOFF
Activity cited by DOJ Since 2022
Estimated attacks Hundreds of thousands of actual or attempted DDoS attacks
Reported targets Education, government, gaming and other online services
Status Domains seized

What Was NightmareStresser?

NightmareStresser operated as a so-called booter or stresser service.

These platforms are commonly advertised as tools that customers can use to stress-test their own servers and networks.

However, authorities say services such as NightmareStresser lower the technical barrier to conducting unauthorized DDoS attacks by allowing customers to pay for attack capabilities rather than building their own infrastructure.

A DDoS attack attempts to overwhelm a target with traffic or requests until legitimate users can no longer access the service.

The basic model is:

Customer selects target

↓

DDoS infrastructure generates attack traffic

↓

Target receives overwhelming traffic

↓

Resources become exhausted

↓

Legitimate users experience disruption or outage

This turns DDoS capability into an easily accessible service.

Hundreds of Thousands of Attacks Since 2022

According to the DOJ, NightmareStresser was used to conduct hundreds of thousands of actual or attempted DDoS attacks against victims worldwide since 2022.

Authorities identified targets across sectors including:

  • Educational institutions
  • Government agencies
  • Gaming platforms
  • Online services
  • Individual internet users

The scale of the operation highlights how DDoS-for-hire platforms can allow relatively inexperienced attackers to generate significant disruption without operating their own large attack infrastructure.

More Than 566,000 Registered Users Reported

Earlier research published by Searchlight Cyber in 2023 indicated that NightmareStresser had grown into a substantial operation.

Researchers identified more than 566,000 registered users and 52 servers associated with the service.

The platform reportedly supported 28 attack methods and advertised attack capacity reaching approximately 200 Gbps.

Customers could select a target IP address or URL, specify ports and launch attacks against different layers of network infrastructure.

Reported subscription prices ranged from roughly €25 to €19,999, depending on attack duration, concurrency and other capabilities.

These historical figures provide an indication of the scale NightmareStresser had reached, but they should not be interpreted as meaning every registered account was actively conducting attacks.

Layer 4 and Layer 7 Attacks

NightmareStresser reportedly offered attacks targeting multiple layers of internet infrastructure.

Layer 4 Attacks

Transport-layer attacks typically attempt to overwhelm networking resources using protocols such as:

  • TCP
  • UDP

The objective may be to consume bandwidth, connection tables or other networking resources.

Layer 7 Attacks

Application-layer attacks instead target services such as websites and APIs.

Rather than simply generating large volumes of network traffic, these attacks can generate large numbers of apparently legitimate application requests.

This can consume:

  • Web server resources
  • Application processing capacity
  • Database connections
  • API resources
  • Backend infrastructure

Supporting multiple attack types makes a DDoS-for-hire service capable of targeting a wider range of systems.

Two Domains Seized

The enforcement action targeted two domains associated with NightmareStresser:

nightmare-stresser[.]com

and

nightmarestresser[.]org

Visitors to the seized infrastructure are now presented with a law-enforcement seizure notice.

The banner states that the websites were seized as part of coordinated law-enforcement action against illegal DDoS-for-hire services.

Taking control of the domains disrupts an important part of the service's customer-facing infrastructure, making it harder for operators and customers to continue using the platform through those addresses.

NightmareStresser Had Already Been Targeted Before

This is not the first time U.S. authorities have targeted NightmareStresser infrastructure.

In December 2022, nightmarestresser[.]com was among 48 domains seized by the DOJ during an earlier crackdown on DDoS-for-hire services.

The platform's continued presence after that action illustrates one of the difficulties associated with disrupting cybercrime-as-a-service operations.

Taking down a domain does not necessarily eliminate:

  • Backend infrastructure
  • Administrators
  • Customer databases
  • Payment systems
  • Attack servers
  • Botnets
  • Communication channels
  • Alternative domains

Operators can potentially move to new infrastructure unless authorities also disrupt the broader ecosystem supporting the service.

Operation PowerOFF

The latest seizure forms part of Operation PowerOFF, an international initiative focused on disrupting DDoS-for-hire services and pursuing their operators and users.

Operation PowerOFF brings together law-enforcement agencies from multiple countries to target the infrastructure behind booter and stresser services.

The initiative has involved:

  • Domain seizures
  • Infrastructure disruption
  • Search warrants
  • Arrests
  • Criminal charges
  • Identification of service users
  • Public-awareness campaigns

The DOJ says investigations conducted by prosecutors and investigators in Anchorage and Los Angeles over the past eight years have resulted in charges against 12 defendants accused of facilitating DDoS-for-hire services and the seizure of more than 100 related internet domains.

Earlier Operation PowerOFF Action Hit 53 Domains

The NightmareStresser seizure follows another significant Operation PowerOFF action earlier in 2026.

In April, authorities disrupted 53 domains associated with commercial DDoS services, while four people were arrested in connection with related operations.

European authorities said approximately 75,000 users of the targeted services had been identified during that operation.

The continued enforcement activity indicates that authorities are targeting both the operators supplying DDoS services and the broader ecosystem supporting them.

DDoS-as-a-Service Lowers the Barrier to Cybercrime

Operating a large-scale DDoS campaign traditionally required considerable infrastructure and technical expertise.

An attacker might need access to:

Compromised devices

↓

Command-and-control infrastructure

↓

Attack scripts

↓

Traffic-generation capabilities

↓

Infrastructure capable of coordinating attacks

DDoS-for-hire platforms change this model.

The customer may only need to:

Create account

↓

Purchase subscription

↓

Enter target

↓

Select attack parameters

↓

Launch attack

The technical complexity is handled by the service provider.

This cybercrime-as-a-service model significantly lowers the barrier to launching disruptive attacks.

“Stresser” Branding Does Not Make Unauthorized Attacks Legal

Some DDoS services present themselves as legitimate network stress-testing platforms.

There are legitimate reasons for organizations to conduct controlled load and resilience testing against infrastructure they own or have explicit authorization to test.

The distinction is authorization.

Using such infrastructure against a third-party system without permission can constitute criminal activity.

The DOJ specifically warns that booter services are frequently marketed as stress-testing utilities while being used to facilitate attacks against victims in the United States and elsewhere.

DDoS Remains a Significant Business Risk

Although DDoS attacks typically focus on availability rather than directly stealing information, their business impact can still be substantial.

Successful attacks can cause:

  • Website outages
  • API disruption
  • Gaming-service interruptions
  • Customer-access failures
  • Payment-service disruption
  • Operational downtime
  • Lost revenue
  • Increased infrastructure costs
  • Reputational damage

DDoS attacks may also be used alongside other malicious activity.

For example, defenders occupied with an availability incident may have less visibility into unrelated intrusion activity occurring elsewhere in the environment.

Organizations should therefore avoid treating DDoS solely as a bandwidth-management issue.

Defensive Measures Against DDoS Attacks

Organizations operating public-facing infrastructure should maintain layered DDoS defenses.

Important controls include:

  • DDoS mitigation services
  • Content delivery networks
  • Web application firewalls
  • Rate limiting
  • Traffic filtering
  • Anycast infrastructure
  • Network-level anomaly detection
  • Application-layer request monitoring
  • Upstream ISP coordination
  • Autoscaling where appropriate
  • Tested incident-response procedures

Organizations should also establish baseline traffic patterns so abnormal spikes can be identified quickly.

Prepare Before an Attack Happens

DDoS response planning should happen before an outage begins.

Security and infrastructure teams should know:

Who contacts the ISP?

Who activates the DDoS provider?

Who manages DNS changes?

Who communicates with customers?

Who preserves attack telemetry?

Who coordinates with law enforcement?

These decisions become much harder to make when production services are already unavailable.

Organizations should periodically test their DDoS response procedures and verify that mitigation providers can handle expected attack scenarios.

Security Takeaway

The seizure of NightmareStresser demonstrates the continuing international effort to dismantle the infrastructure supporting DDoS-as-a-Service operations.

According to U.S. authorities, NightmareStresser facilitated hundreds of thousands of actual or attempted attacks worldwide since 2022, targeting educational institutions, government agencies, gaming platforms and other victims.

Historical research also illustrates the platform's scale, with more than 566,000 registered users, 52 servers and dozens of available attack methods identified in 2023.

The latest operation can be summarized as:

DDoS-for-Hire Platform

→ Hundreds of Thousands of Attacks/Attempts

→ International Investigation

→ Court-Authorized Seizure

→ NightmareStresser Domains Taken Offline

→ Operation PowerOFF Continues

However, a domain seizure should not automatically be interpreted as destruction of every technical component behind the operation.

The DOJ announcement focuses on the seizure of NightmareStresser's domains and does not establish that every backend attack server, botnet or related piece of infrastructure has been eliminated.

For defenders, the broader lesson remains unchanged: DDoS capabilities have become commoditized, allowing attackers to rent disruptive capacity instead of developing it themselves.

Organizations running critical internet-facing services should therefore combine technical DDoS mitigation with monitoring, incident-response planning and coordination with upstream providers.

Filed by Zentrya One Desk · CyberNews desk  ·  Follow Zentrya One on LinkedIn

Related reporting

Threat Intel

Threat Intelligence Alone Cannot Close the Growing Exploitation Gap

Threat intelligence alone cannot stop rapidly evolving cyberattacks. Learn how security validation, risk-based vulnerability management and faster remediation can help organizations close the growing exploitation gap.

The Daily Brief

Stay informed. Stay prepared. Stay one step ahead.

One brief each morning: the advisories that matter, the noise removed.

Double opt-in. One-click unsubscribe in every email. We never sell addresses.