The FBI has seized domains supporting NightmareStresser, disrupting one of the world’s longest-running DDoS-for-hire operations.
The court-authorized action targets a service that allegedly enabled paying customers to overwhelm online services with malicious traffic, cutting off legitimate users.
According to a seizure-warrant affidavit cited by the U.S. Department of Justice, NightmareStresser was used to launch hundreds of thousands of actual or attempted DDoS attacks against victims worldwide since 2022.
Authorities took control of nightmare-stresser[.]com and nightmarestresser[.]org, replacing their content with law-enforcement seizure notices.
NightmareStresser operated as a “booter” or “stresser,” names for commercial DDoS platforms. Although services in this market may present themselves as legitimate network-testing tools, they give customers access to attack infrastructure capable of flooding a target with illegitimate requests or traffic.
This lowers the barrier to cybercrime because customers need not build malware, compromise devices or manage a botnet.
The impact extends beyond a temporarily unavailable website. The Justice Department said booter attacks have affected educational institutions, government agencies, gaming platforms and millions of people worldwide.
Large traffic floods can consume bandwidth and server resources, degrade upstream internet services and, in severe cases, completely disrupt a target’s connectivity.
The FBI Anchorage Field Office conducted the seizures with the Royal Canadian Mounted Police’s Federal Policing Northwest Region.
According to the official announcement published by the U.S. Department of Justice, the operation was designed to dismantle infrastructure facilitating attacks against victims in Alaska, across the United States and internationally; the announcement did not disclose arrests or charges specifically tied to this latest NightmareStresser action.
Assistant U.S. Attorneys Adam Alexander and Ainsley McNerney are prosecuting the matter.
The takedown forms part of Operation PowerOFF, a continuing multinational campaign focused on dismantling DDoS-for-hire infrastructure and identifying its administrators and users.
Coordinated by Europol’s European Cybercrime Centre and Joint Cybercrime Action Taskforce, the initiative brings together authorities from the United States, Canada, Europe, Asia, Australia and South America.
Europol warns that inexpensive, click-to-launch services can attract low-skilled users while causing serious financial damage and interrupting access to banking, government and police services.
This action also extends a sustained U.S. crackdown. During the past eight years, Justice Department cases involving investigators and prosecutors in Anchorage and Los Angeles have charged 12 defendants accused of facilitating DDoS-for-hire services and resulted in the seizure of more than 100 associated domains.
Domain seizures can immediately remove customer-facing portals and disrupt payments or attack management, but they do not automatically eliminate every backend server or prevent operators from rebuilding elsewhere.
The NightmareStresser intervention nevertheless raises operational costs, preserves evidence and sends a clear warning: purchasing a booter attack is not anonymous or lawful. The FBI says using such services can trigger prosecution under the Computer Fraud and Abuse Act, alongside device seizures, imprisonment and fines.
Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC

