FBI seizes NightmareStresser domains in DDoS-for-hire crackdown
DDoS attacks are no longer available with the click of a button.

Miguel Candela/SOPA/LightRocket/Getty Images
- The FBI and RCMP seized domains linked to NightmareStresser, a DDoS-for-hire service.
- Researchers say NightmareStresser had over 566,000 users and 52 servers ready for attacks.
- The DOJ alleges the service helped launch or attempt hundreds of thousands of attacks since 2022.
- The seizure is part of Operation PowerOFF, an international campaign against DDoS-for-hire services.
Key Takeaways by nexos.ai, reviewed by Cybernews staff.
In coordination with the Royal Canadian Mounted Police (RCMP), the FBI seized internet domains linked to NightmareStresser, one of the world’s longest-running DDoS-for-hire services.
NightmareStresser is a so-called “booter” or “stresser” service that allows cybercriminals to launch distributed denial-of-service (DDoS) attacks against unsuspecting victims. Basically, it offered criminals the opportunity to launch a DDoS attack without the technical skills and know-how to operate a botnet.
According to Searchlight Cybersecurity researchers, the platform had over 566,000 registered users and 52 servers ready to conduct DDoS attacks.
Depending on the target, duration of the attack, and the number of simultaneous attacks, subscription prices varied from approximately €25 to €20,000. The cheapest subscription allowed 1,800 seconds of attack time and 1 concurrent attack, while the most expensive option offered 86,400 seconds of attack time and 400 concurrent attacks.
Such attacks can significantly affect internet services and can completely disrupt internet connections. That’s why the US Department of Justice (DOJ) is continuously hunting down domains and operators of DDoS-for-hire services.
“In recent years, booter services have continued to proliferate as they offer a low barrier to entry for users looking to engage in cybercriminal activity,” the DOJ says in a press release.
The Justice Department claims that NightmareStresser facilitated hundreds of thousands of attacks or attempted attacks over the years.
The DOJ alleges that the booter service has been targeting educational institutions, government agencies, gaming platforms, and millions of people worldwide since 2022.
Stay updated with our latest stories and follow us on social media
Be the first to discover new stories, ideas, and updates from our team.
With assistance from the Canadian police, the FBI has seized an undisclosed number of domains associated with NightmareStresser. Visitors are now presented with a splash page detailing why the site was taken offline.
The law enforcement actions were part of Operation PowerOFF, an ongoing international effort targeting DDoS-for-hire infrastructure and the people who operate or use the services.
Previously, the DOJ charged 12 defendants who facilitated DDoS-for-hire services and seized more than 100 domains associated with these booter services.
In December 2024, law enforcement authorities from 15 countries took down 27 DDoS service platforms. In addition, 3 administrators were arrested in France and Germany, and 300 users were identified.
Lastly, more than 250 warning letters, over 2,000 emails, and knock-and-talks were used to deter users of illegal online services.
DDoS attacks are no longer available with the click of a button.