NightmareStresser DDoS-for-hire domains seized — the same brand the FBI already took down once
By Sethu Satheesh · 18 Sept 2026 · 12 min read
Threat Actor: Unknown (operators of NightmareStresser, unnamed; claimed to operate under Russian jurisdiction, unverified) · Target: Educational institutions, government agencies, gaming platforms, and members of the public in the US and worldwide
Source: www.justice.gov
Executive Summary
On 15 September 2026 the FBI's Anchorage Field Office and the Royal Canadian Mounted Police seized the domains nightmare-stresser[.]com and nightmarestresser[.]org, taking offline a DDoS-for-hire "booter" service that, by the government's own account, had been used to launch hundreds of thousands of actual or attempted denial-of-service attacks against victims worldwide since at least 20221. The action is the latest wave of Operation PowerOFF, a joint FBI-Europol effort against booter and stresser services that began in 2018 and has now charged twelve defendants and seized more than 100 domains12.
No one was arrested in this specific action, and the Justice Department did not name an operator or state a country of origin1. A threat researcher who spoke to press on the record filled in what the government didn't: NightmareStresser's own marketing claimed the service operated under the laws of the Russian Federation — a jurisdictional shield that, if true, makes prosecuting whoever ran it considerably harder even if they're identified3. That marketing was aggressive and specific. The service advertised itself, on its own now-seized website, as "the only DDoS tool available 24x7, running non-stop for over 8 years" and boasted "no vanishing acts, no broken promises." One outlet's reporting states plainly that this claim is false on its face: a domain linked to NightmareStresser was already seized once before, in the December 2022 wave of the same operation4. Whatever ran under that name in September 2026 either survived that seizure under a different domain or rebuilt itself afterward — either way, "never went down" describes a service that the FBI had already taken down once.
The scale, per a late-2023 report from threat intelligence firm Searchlight Cyber that multiple outlets cite, was substantial for a service of this kind: more than 566,000 registered users and 52 dedicated servers capable of Layer 4 (UDP/TCP) and Layer 7 attacks up to 200 Gbps, sold with cryptocurrency payment and a referral program that paid users for every renewal or purchase made by people they'd referred, indefinitely45. A researcher interviewed by CyberScoop put the more usual scale of a service like this in context differently — "tens of thousands" of active users, mostly "script kiddies... oftentimes for pranks" — a real tension between the vendor-reported historical high-water mark and what a working botnet-for-hire's active user base typically looks like day to day3.
Verification of Claims
-
Claim: NightmareStresser had "more than 8 years" of continuous uptime with "no vanishing acts." → False → This is the service's own marketing copy, preserved and quoted by The Hacker News from the seized site before takedown4. The same report states that a domain linked to NightmareStresser ("nightmarestresser[.]com") was already among the 48 domains seized in the December 2022 wave of Operation PowerOFF46. A service whose domain has already been seized by the FBI once cannot honestly claim it has never gone down; at minimum, the operators either lost and regained control of that domain, or migrated to a new one and inherited the brand, neither of which is "no vanishing acts."
-
Claim: NightmareStresser had 566,000+ registered users. → Assessed, Not Confirmed → Sourced to a late-2023 report by Searchlight Cyber, cited via The Hacker News and Help Net Security45. The figure is a vendor's historical assessment from nearly three years before the September 2026 seizure, not a court-established or government-confirmed count, and does not distinguish active users from cumulative signups. CyberScoop separately reported a threat researcher's estimate of "tens of thousands" of actual users, a meaningfully smaller figure describing current rather than cumulative usage3.
-
Claim: NightmareStresser operated under Russian jurisdiction. → Unverified → Reported by CyberScoop, attributed to the service's own claims as relayed by Infoblox threat researcher Zach Edwards, not to any government confirmation: "the service claimed it operated under the laws of Russia"3. The Justice Department's press release does not name a country of origin or an operator1. This is the operators' own unverified assertion, useful context for why enforcement stopped at a domain seizure rather than an arrest, but not established fact.
Timeline
| Date | Actor | Event | Source |
|---|---|---|---|
| Dec 2018 | FBI / Dutch National Police | Operation PowerOFF begins; first wave seizes 15 booter domains | 2 |
| No later than 2022 | NightmareStresser operators | Service operating under the NightmareStresser name, per DOJ's affidavit-sourced assessment | 1 |
| Dec 2022 | FBI / DOJ (C.D. Cal. and D. Alaska) | 48 domains seized, 6 US defendants charged; a domain linked to NightmareStresser is among those seized | 46 |
| Late 2023 | Searchlight Cyber | Reports NightmareStresser had 566,000+ registered users, 52 dedicated servers, up to 200 Gbps capability | 45 |
| May 2023 | Operation PowerOFF | 13 further domains seized | 2 |
| Dec 2024 | Operation PowerOFF | Additional takedowns | 2 |
| April 2026 | Europol / Operation PowerOFF | 53 domains disrupted, 4 arrests, 75,000+ users affected | 4 |
| Sept 15, 2026 | FBI Anchorage / RCMP | nightmare-stresser[.]com and nightmarestresser[.]org seized under a District of Alaska warrant |
1 |
| Sept 17, 2026 | CyberScoop / The Hacker News / Help Net Security | Seizure and service history reported, including the researcher-sourced Russian-jurisdiction claim | 345 |
Operation Anatomy
The service
NightmareStresser presented itself publicly as a stress-testing tool, the standard fig leaf booter services use to avoid outright admitting illegality, while its own site content contradicted that framing directly: "advanced Layer 4 amplification methods and various bypasses at Layer 4 over UDP/TCP and Layer 7, claiming they can defeat CAPTCHAs, geoblocks, and rate limits"4. Per Searchlight Cyber's 2023 assessment, the backend ran on 52 dedicated servers, offered attacks up to 200 Gbps, and gave customers a control panel to select target IP or URL, port number, and number of concurrent attacks45. A "Stop All" button let a customer halt every running Layer 4 or Layer 7 flood with one click4. Payment was accepted in cryptocurrency, and an "advanced referral system" paid the referring user credit for every purchase or renewal their referral made, "over time" — a recurring-revenue affiliate structure more commonly associated with legitimate SaaS products than criminal infrastructure4.
Infrastructure
Internet Archive snapshots examined by The Hacker News show the nightmarestresser[.]org domain was itself protected against DDoS attacks by a commercial web infrastructure provider, BlazingFast — a booter service paying a third party to keep its own storefront online against the very kind of attack it sold4.
Victims
The Justice Department describes the victim population broadly: "educational institutions, government agencies, gaming platforms and millions of people," both in the District of Alaska and worldwide1. No specific named victim organization or incident is cited in the government's release; this is a characterization of the service's customer base's targeting pattern, assessed from the seizure warrant affidavit, not a list of confirmed victims.
Loading diagram...
Threat Actor Profile
- Name: NightmareStresser (self-branded). No operator named by any government source reviewed13.
- Attribution confidence: None established by law enforcement. The claim of Russian jurisdiction is the operators' own marketing, relayed by a private researcher, not a government finding3.
- Motivation: Financial — a subscription/pay-per-attack booter business with a referral-based growth model, not an ideologically motivated actor4.
- Customer base (not the operators themselves): Per CyberScoop's source, predominantly "script kiddies... oftentimes for pranks or for some sort of obscure political agenda," historically concentrated against gaming servers and streamers3.
- Operational history: At least since 2022 under the NightmareStresser name per DOJ's affidavit-sourced assessment1; the brand's own claim of "8 years" would place its origin closer to 2018, coinciding with Operation PowerOFF's own start date — unverified, but not implausible for a service of this type124.
MITRE ATT&CK (IDs checked live on attack.mitre.org, 18 September 2026):
| ID | Technique | Basis |
|---|---|---|
| T1583.006 | Acquire Infrastructure: Web Services | Storefront domains, BlazingFast-protected hosting, cryptocurrency payment processing4 |
| T1498.001 | Network Denial of Service: Direct Network Flood | Layer 4 UDP/TCP flood capability advertised by the service4 |
| T1498.002 | Network Denial of Service: Reflection Amplification | "Advanced Layer 4 amplification methods" advertised on the seized site4 |
This entry describes the service NightmareStresser sold to its customers, who are the actual technique operators in each attack; the platform itself is infrastructure-for-hire rather than a single intrusion campaign.
Technical Indicators
seized_domains:
- "nightmare-stresser[.]com"
- "nightmarestresser[.]org"
infrastructure_provider_named_in_reporting:
- "BlazingFast (DDoS protection for nightmarestresser[.]org, per Internet Archive snapshots)"
prior_related_seizure:
- "nightmarestresser[.]com — reported among the 48 domains seized in the December 2022 wave of Operation PowerOFF"
seizure_statutory_basis:
- "18 U.S.C. § 981(a)(1)(A) and (b) — civil forfeiture of property involved in money laundering / traceable to unlawful activity"
- "18 U.S.C. § 982(b)(1) — criminal forfeiture procedures"
- "18 U.S.C. § 1030(i)(1)(A) — forfeiture under the Computer Fraud and Abuse Act"
- "21 U.S.C. § 853 — criminal forfeiture procedures (incorporated by reference)"
scale_reported_by_searchlight_cyber_2023:
registered_users: "566,000+"
dedicated_servers: 52
max_advertised_throughput: "200 Gbps"
layers_targeted: ["Layer 4 (UDP/TCP)", "Layer 7"]
network_iocs: none disclosed beyond the seized domains
file_hashes: none disclosed — this is a web-based subscription service, not malwareLegal and Regulatory Response
Seizure. Court-authorized seizure warrant issued by the US District Court for the District of Alaska, executed 15 September 2026 by FBI Anchorage Field Office in coordination with the Royal Canadian Mounted Police, Federal Policing Northwest Region1. No indictment or arrest was announced alongside this specific seizure1.
Prosecutors. Assistant US Attorneys Adam Alexander and Ainsley McNerney, District of Alaska1.
Program context. Operation PowerOFF is a standing joint effort among the FBI, Europol, the Dutch National Police, Germany's Federal Criminal Police Office, Poland's Cybercrime Police and the UK National Crime Agency, running since December 20182. Prior waves: December 2018 (15 domains, with the Dutch National Police); December 2022 (48 domains, 6 US defendants charged, including a domain linked to NightmareStresser)46; May 2023 (13 more domains)2; December 2024 (further takedowns)2; April 2026 (53 domains disrupted, 4 arrests, more than 75,000 users affected, per Europol)4. Total across the program to date: more than 100 domains, twelve defendants charged1.
No named defendant in this action. The DOJ release states the investigation "builds on the success of prior cases by targeting all known booter sites, shutting down as many as possible, and undertaking a public education campaign" — language describing an infrastructure-disruption and deterrence strategy rather than an imminent prosecution1.
Impact Assessment
- Domains seized in this action: Confirmed, 2 (
nightmare-stresser[.]com,nightmarestresser[.]org)14. - Attacks attributed to the service since 2022: Reported, "hundreds of thousands of actual or attempted" attacks, per the FBI's seizure warrant affidavit1.
- Registered users: Reported (vendor estimate, late 2023), 566,000+45; separately estimated as "tens of thousands" active by an independent researcher speaking in September 20263.
- Operators identified or arrested: None, as of this action13.
- Total domains seized under Operation PowerOFF to date: Confirmed, more than 100, across all waves since 20181.
- Total defendants charged under Operation PowerOFF to date: Confirmed, 121.
- Whether the takedown will meaningfully reduce booter-service availability: Assessed, unlikely to be durable — per the CyberScoop-quoted researcher, "these booter services are like playing a game of Whac-A-Mole... these underground networks quickly shift to new providers when one is taken down"3.
Lessons and Defensive Recommendations
For organizations that might be targeted
- Booter-service customers overwhelmingly target gaming platforms, streamers, schools and public-sector sites — categories that often lack enterprise-grade DDoS mitigation. If your organization fits one of those categories, standing DDoS protection (not an incident-response plan you'll set up after the first attack) is the actual mitigation; law enforcement seizures of booter infrastructure are welcome but, per the researcher record here, not durable.
- A referral-driven, subscription-based booter service is a business, and businesses have customer lists, payment records and infrastructure vendors. Domain seizure notices are a useful signal to check whether your organization was named as a target in any subsequently unsealed affidavit.
For platforms and infrastructure providers
- BlazingFast (or any DDoS-protection provider) protecting a service that is itself a DDoS-for-hire storefront is a detectable pattern: a "stress testing" customer whose own traffic profile looks like it needs enterprise DDoS mitigation is a red flag worth screening for at onboarding.
- Cryptocurrency payment plus an uncapped, indefinite referral-commission structure is a recognizable criminal-service business model, not just a booter-specific one; the same pattern shows up in access-broker and DDoS markets alike, and is a useful heuristic for infrastructure abuse teams.
For researchers and journalists
- Treat a criminal service's self-reported uptime and scale claims exactly as skeptically as any other advertising copy. In this case the claim was directly falsifiable against the government's own prior seizure record, and nobody at the point of initial coverage flagged the contradiction — it took a follow-up piece cross-referencing Internet Archive snapshots against a 2022 DOJ release to catch it46.
- Vendor-reported user counts (here, Searchlight Cyber's 566,000 figure) and researcher field estimates ("tens of thousands" active) are answering different questions — cumulative signups versus a working criminal customer base — and conflating them overstates or understates the service's real reach depending on which framing a story leads with.
Sources
Footnotes
-
FBI Seizes DDoS-for-Hire Domains as Part of Continuing District of Alaska Crackdown on 'Booter' and 'Stresser' DDoS Services — US Attorney's Office, District of Alaska, 15 September 2026 ↩ ↩2 ↩3 ↩4 ↩5 ↩6 ↩7 ↩8 ↩9 ↩10 ↩11 ↩12 ↩13 ↩14 ↩15 ↩16 ↩17 ↩18 ↩19 ↩20
-
Operation PowerOFF — Wikipedia, citing DOJ and Europol releases 2018–2026 ↩ ↩2 ↩3 ↩4 ↩5 ↩6 ↩7 ↩8
-
Authorities seize popular, long-running DDoS-for-hire service domains — CyberScoop, Matt Kapko, 17 September 2026 (quoting Zach Edwards, Infoblox) ↩ ↩2 ↩3 ↩4 ↩5 ↩6 ↩7 ↩8 ↩9 ↩10 ↩11
-
U.S. Seizes NightmareStresser Domains Linked to Hundreds of Thousands of DDoS Attacks — The Hacker News, Ravie Lakshmanan, 17 September 2026 ↩ ↩2 ↩3 ↩4 ↩5 ↩6 ↩7 ↩8 ↩9 ↩10 ↩11 ↩12 ↩13 ↩14 ↩15 ↩16 ↩17 ↩18 ↩19 ↩20 ↩21 ↩22 ↩23 ↩24
-
FBI takes down one of the longest-running DDoS-for-hire services — Help Net Security, Sinisa Markovic, 17 September 2026 ↩ ↩2 ↩3 ↩4 ↩5 ↩6
-
Federal Prosecutors in Los Angeles and Alaska Charge 6 Defendants with Operating Websites that Offered Computer Attack Services — US Department of Justice, 14 December 2022 ↩ ↩2 ↩3 ↩4
Related Research
LockBit, BlackSuit and Play didn't run their own servers. They rented them from a company in St Petersburg that answered no abuse reports and no takedown requests, and billed like any other host.
Cybernews found an exposed server revealing a two-year operation that brute-forced weak credentials on end-of-life PPTP/L2TP VPN devices to build an 87,000-IP residential proxy network, resold to platforms including VPN Pure, using a jailbroken Claude Code to automate the hunt.
A dark-web service called Nexus sold infrared and ultraviolet scans of 153 million North American driver's licences, traced by Krebs to identity-verification vendor IDScan.net. The vendor's own documentation shows its cloud retained every scan indefinitely by default.