Authorities seize popular, long-running DDoS-for-hire service domains
At a glance
- Severity
- Low
- Used in attacks
- No flaws named
- Reported by
- 1 outlet
Get our latest cybersecurity news first on Google.
Authorities seized the primary domain and other websites linked to NightmareStresser, one of the longest-running and most popular distributed denial-of-service operations used by cybercriminals globally, the Justice Department said Tuesday.
Cybercriminals of various motivations used the DDoS-for-hire service to launch hundreds of thousands of DDoS attacks or attempted attacks since at least 2022, officials said.
The takedown, part of an ongoing globally coordinated effort dubbed “Operation PowerOFF,” marks law enforcement’s continued targeting of IP stressers or DDoS booters that inundate websites, servers and networks with junk traffic, rendering legitimate sites inaccessible. The seizures were executed by the FBI Anchorage field office and the Royal Canadian Mounted Police.
Officials didn’t name the operators of NightmareStresser or identify its country of origin, but the service claimed it operated under the laws of Russia, Zach Edwards, staff threat researcher at Infoblox told CyberScoop.
The court-ordered seizure of NightmareStresser’s primary domain, which operated openly on the public web and now displays a seizure notice, is a positive development in the fight against DDoS-for-hire threat actors, Edwards said. Yet, he added, “it’s somewhat shocking that it’s taken law enforcement this long to take action.”
Authorities said they’ve seized more than 100 domains associated with DDoS-for-hire services since 2018.
Despite those efforts, DDoS-for-hire tools remain prolific and easily accessible, often including tutorials that allow non-tech savvy people to initiate attacks on various organizations.
“The vast majority of people who actually use DDoS services like NightmareStresser are script kiddies, oftentimes for pranks or for some sort of obscure political agenda. These services have been heavily used against gaming servers and streamers,” Edwards said.
Officials said NightmareStresser’s customers targeted various victims in the United States and abroad, including educational institutions, government agencies, gaming platforms and millions of people.
The DDoS-for-hire service’s operators claimed tens of thousands of users, Edwards said. “NightmareStresser is unique because of how long they’ve operated, their aggressive marketing which was pretty open about supporting illegal use cases, and their affiliate program which was used to reward partners,” he added.
Authorities are now likely attempting to identify the operators of NightmareStresser, its business partners and people who used the service, according to Edwards.
“Unfortunately for law enforcement, threat actors behind NightmareStresser claimed they were operating under the laws of the Russian Federation, which is a strong sign that it may be challenging to bring these folks to justice, even if they are known and doxxed,” he said.
The impact of the seizures may also be temporary, at best. “The reality is that these booter services are like playing a game of Whac-A-Mole,” Edwards said. “There’s always another suspicious service operating similar DDoS products, and these underground networks quickly shift to new providers when one is taken down.”
Latest Podcasts
Government
What’s next for CISA's CDM program that gives cybersecurity tools to federal agencies
Supreme Court denies Trump request to allow USPS mail ballot changes
Cyberattack causes a flight delay? Airlines won’t owe you a hotel or meal
Hawley probes OpenAI over Hugging Face breach
Technology
Researchers say OpenAI agents were behind May hacking campaign targeting RubyGems
European parliament members call for slowdown of Serbia’s EU entry over spyware use
The G7 tells industry to hurry up and prep for post-quantum encryption
FCC proposes public scorecard to rate telecoms on anti-robocall efforts
Threats
Cisco warns customers of actively exploited zero-day in email gateways
GitLab's critical flaw is already drawing internet-wide probes
Chinese espionage groups swarm to exploit triple-link chain of zero-days
Lawmakers call on Commerce to sanction hackers-for-hire
Policy
Governments ‘buying time’ in race between innovation, security, national cyber director says
FTC rescinds policy statement requiring health apps to notify customers after a breach
FBI cyber chief worries private sector not sharing enough cyber threat information
Wyden seeks upgraded NSA security guidance on commercial VPN use
Originally published by CyberScoop. © CyberScoop. Written by Greg Otto.
Fastnexa security experts
Dealing with this in your own company?
If this story touches software, suppliers or systems you use, a Fastnexa security expert can tell you what it means for you and what to do first.
Think you’ve already been hit? Don’t wait on a form: call or WhatsApp +1 (732) 454 2616. We reply within 1 hour, 24/7. Emergency help →
Coverage
One outlet has carried this so far.
2026-09-17 13:37 UTC
Related stories
- Times Car confirms data breach affecting 6.6 million user accounts
BleepingComputer · 2026-09-28
- Carbonato Botnet Puts an AI Agent on Hacked Docker Hosts
Dark Reading · 2026-09-28
- ShinyHunters exploiting workarounds for Oracle PeopleSoft bug, Mandiant warns
The Record · 2026-09-28
- Hackers Use NeedyMantis to Maintain Long-Term Access in Breached Networks
The Hacker News · 2026-09-28
- JadePuffer AI Actor Compromises Azure Tenant in Destructive Cloud Attack
Dark Reading · 2026-09-28