GBHackers

FBI Seizes NightmareStresser DDoS-for-Hire Domains Used in Hundreds of Thousands of Attacks


The FBI has seized internet domains linked to NightmareStresser, a long-standing distributed denial-of-service (DDoS)-for-hire platform allegedly used to launch hundreds of thousands of attacks or attempted attacks worldwide since 2022.

The U.S. Attorney’s Office for the District of Alaska announced the action, which targets the infrastructure that allowed paying customers to overwhelm victims’ networks and internet connections.

The FBI Anchorage led the seizure with the Royal Canadian Mounted Police’s Federal Policing Northwest Region as part of the broader international Operation PowerOFF campaign to combat illegal booter and stresser services.

FBI Seizes NightmareStresser

NightmareStresser operated as a “booter” or “stresser,” a commercialized attack service that lowers the technical and financial barriers to DDoS abuse.

These platforms typically market traffic floods as a subscription service, letting users choose a target and order disruptive traffic volumes without building their own botnet or attack infrastructure.

Investigators have reported that the service affected victims in Alaska, across the United States, and internationally. Targets included educational institutions, government agencies, gaming platforms, and individual internet users, showing the widespread impact DDoS-for-hire operations can have on organizations and consumers alike.

In a DDoS incident, attackers distribute traffic or requests across numerous compromised or misused systems, exhausting bandwidth, computing resources, connection tables, or application capacity.

The immediate effects can range from latency and service degradation to a complete loss of connectivity. “Booting” refers to forcing a computer or network offline, a term commonly used in gaming-related attack communities.

However, the impact extends well beyond gaming: sustained attacks can interrupt public-facing services, prevent legitimate users from accessing online resources, and create costly operational and incident-response burdens for targeted entities.

The seizure is part of Operation PowerOFF, an ongoing multinational law enforcement effort on dismantle DDoS-for-hire infrastructure and pursue both service administrators and users.

Authorities describe this operation as a disruption effort aimed at the infrastructure that facilitates attacks against Alaskan and other U.S. victims.

Domain seizures can immediately limit a platform’s visibility, payment flow, customer access, and command interface. However, operators may attempt to re-establish services elsewhere. Therefore, the operation combines infrastructure actions with investigations aimed at identifying the individuals behind these services.

The District of Alaska notes that this latest action builds on eight years of cases involving prosecutors and investigators from Anchorage and Los Angeles.

In previous efforts, the Justice Department charged 12 defendants accused of facilitating DDoS-for-hire services and seized more than 100 associated domains.

Assistant U.S. Attorneys Adam Alexander and Ainsley McNerney are prosecuting the current case. This situation emphasizes that purchasing DDoS attacks is not just a harmless online prank: even low-cost, accessible booter services can disrupt essential connectivity and expose both operators and customers to criminal enforcement.

Organizations should maintain DDoS mitigation plans, coordinate with providers, and quickly preserve evidence when attacks occur.

Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC



Source link