VYPR
breachPublished Sep 17, 2026· 3 sources

FBI Seizes NightmareStresser, a Long-Running DDoS-for-Hire Service

The FBI has dismantled NightmareStresser, one of the longest-operating DDoS-for-hire services, seizing its domains and disrupting its illegal operations.

The Federal Bureau of Investigation (FBI) has successfully seized the domains associated with NightmareStresser, a notorious "booter" service that has been facilitating Distributed Denial of Service (DDoS) attacks for years. This action, part of a coordinated international law enforcement effort, aims to dismantle the infrastructure used by cybercriminals to launch disruptive attacks against a wide range of targets.

NightmareStresser is described by officials as one of the longest-running DDoS-for-hire operations in existence. These "booter" services allow individuals to rent out the capability to launch DDoS attacks, overwhelming targeted systems with traffic and rendering them inaccessible. The FBI stated that services like NightmareStresser "allegedly facilitate attacks on a wide array of victims in the United States and abroad, including educational institutions, government agencies, gaming platforms and millions of people."

According to the seizure warrant affidavit, NightmareStresser has been instrumental in launching hundreds of thousands of actual or attempted DDoS attacks against victims globally since at least 2022. The impact of these attacks can range from minor service disruptions to significant financial losses and reputational damage for affected organizations. The FBI's Anchorage Field Office, in collaboration with the Royal Canadian Mounted Police, executed the seizure under Operation PowerOFF, an ongoing initiative targeting illegal cyberattack infrastructure.

This operation builds upon years of investigative work. Over the past eight years, prosecutors and investigators in Anchorage and Los Angeles have charged twelve defendants for running similar DDoS-for-hire services and have seized more than 100 related domains. The current multi-pronged investigation aims to shut down as many booter sites as possible and includes a public education campaign to raise awareness about the dangers and consequences of using such services.

The disruption of NightmareStresser is particularly significant given its longevity and the scale of its operations. Cloudflare's H1 2026 DDoS Threat Report highlighted that DDoS-for-hire platforms, alongside compromised IoT devices and automated tools, continue to lower the barrier for launching large-scale attacks. This seizure represents a crucial step in combating this persistent threat vector.

By taking down NightmareStresser, law enforcement agencies are not only disrupting current attack capabilities but also sending a strong message to potential users and administrators of such services. The goal is to hold accountable those who profit from and enable cyberattacks, thereby enhancing the overall cybersecurity posture for individuals and organizations worldwide.

The seizure notice, prominently displayed by the U.S. Department of Justice, serves as a public declaration of the successful enforcement action. This coordinated effort underscores the commitment of international law enforcement to combatting cybercrime and protecting critical infrastructure from malicious activities.

The seizure of NightmareStresser's primary domain, which was openly accessible on the public web and now displays a seizure notice, is a significant development. However, experts note that it's surprising it took law enforcement this long to act, given the service's long operational history. The operators of NightmareStresser claimed to operate under Russian jurisdiction, which may present challenges for prosecution even if they are identified.

The U.S. Department of Justice has announced the court-authorized seizure of two additional domains associated with the NightmareStresser DDoS-for-hire service: nightmare-stresser[.]com and nightmarestresser[.]org. This action, part of a joint international law enforcement operation, follows a previous seizure in December 2022 that also targeted a NightmareStresser domain, indicating ongoing efforts to dismantle the platform's infrastructure. The DoJ highlighted that NightmareStresser has been used for hundreds of thousands of attacks since 2022, targeting sectors including education, government, and gaming.

Synthesized by Vypr AI
FBI Seizes NightmareStresser, a Long-Running DDoS-for-Hire Service · VYPR