US takes down NightmareStresser DDoS-for-hire platform
The U.S. Federal Bureau of Investigation (FBI) seized the domains of NightmareStresser, a long-running distributed denial-of-service (DDoS) for-hire platform. NightmareStresser allowed users to rent botnets composed of compromised routers and IoT devices to launch large-scale DDoS attacks targeting various network layers. The service had over 566,000 registered users and could launch attacks up to 200 Gbps. This takedown was part of Operation PowerOFF, a coordinated international law enforcement effort to dismantle criminal DDoS-for-hire infrastructures worldwide. Previous actions under this operation have led to multiple arrests and domain seizures of similar services. The FBI and other agencies continue to target these platforms to reduce the prevalence of DDoS attacks globally.
AI Analysis
Technical Summary
NightmareStresser was a DDoS-for-hire service that enabled anyone to rent access to large botnets consisting of compromised routers and IoT devices to conduct distributed denial-of-service attacks. The platform supported attacks on multiple network layers, including Layer 7 application protocols and Layer 4 TCP/UDP protocols, with attack volumes reaching up to 200 Gbps. It had a large user base exceeding 566,000 registered users and operated 52 dedicated servers. The FBI seized the domains nightmarestresser.com and nightmarestresser.org as part of Operation PowerOFF, an ongoing international law enforcement initiative started in 2018 to dismantle DDoS-for-hire services. This operation has resulted in multiple domain seizures and arrests across various countries, including the U.S., U.K., and Poland. The takedown of NightmareStresser disrupts a major source of criminal DDoS attacks worldwide.
Potential Impact
NightmareStresser facilitated hundreds of thousands of DDoS attacks worldwide since 2022, enabling attackers to disrupt online services and platforms by overwhelming them with traffic. The platform's large scale and accessibility lowered the barrier for launching significant DDoS attacks, impacting victims globally across various sectors. The FBI's seizure of the domains effectively disrupts the operation of this major DDoS-for-hire service, reducing the availability of such criminal infrastructure and potentially decreasing the frequency of related attacks. The coordinated international law enforcement efforts under Operation PowerOFF have also led to arrests and further dismantling of similar services, contributing to broader mitigation of DDoS threats.
Mitigation Recommendations
The FBI seizure of NightmareStresser domains and ongoing Operation PowerOFF enforcement actions have disrupted this DDoS-for-hire platform, effectively mitigating the threat it posed. No direct remediation actions are required by defenders specifically for this platform's takedown. Organizations should continue to implement standard DDoS protection measures as usual, but the removal of NightmareStresser reduces the availability of this particular criminal service. Monitoring law enforcement updates on Operation PowerOFF is recommended for awareness of further takedowns and arrests related to DDoS-for-hire services.
US takes down NightmareStresser DDoS-for-hire platform
Description
The U.S. Federal Bureau of Investigation (FBI) seized the domains of NightmareStresser, a long-running distributed denial-of-service (DDoS) for-hire platform. NightmareStresser allowed users to rent botnets composed of compromised routers and IoT devices to launch large-scale DDoS attacks targeting various network layers. The service had over 566,000 registered users and could launch attacks up to 200 Gbps. This takedown was part of Operation PowerOFF, a coordinated international law enforcement effort to dismantle criminal DDoS-for-hire infrastructures worldwide. Previous actions under this operation have led to multiple arrests and domain seizures of similar services. The FBI and other agencies continue to target these platforms to reduce the prevalence of DDoS attacks globally.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
NightmareStresser was a DDoS-for-hire service that enabled anyone to rent access to large botnets consisting of compromised routers and IoT devices to conduct distributed denial-of-service attacks. The platform supported attacks on multiple network layers, including Layer 7 application protocols and Layer 4 TCP/UDP protocols, with attack volumes reaching up to 200 Gbps. It had a large user base exceeding 566,000 registered users and operated 52 dedicated servers. The FBI seized the domains nightmarestresser.com and nightmarestresser.org as part of Operation PowerOFF, an ongoing international law enforcement initiative started in 2018 to dismantle DDoS-for-hire services. This operation has resulted in multiple domain seizures and arrests across various countries, including the U.S., U.K., and Poland. The takedown of NightmareStresser disrupts a major source of criminal DDoS attacks worldwide.
Potential Impact
NightmareStresser facilitated hundreds of thousands of DDoS attacks worldwide since 2022, enabling attackers to disrupt online services and platforms by overwhelming them with traffic. The platform's large scale and accessibility lowered the barrier for launching significant DDoS attacks, impacting victims globally across various sectors. The FBI's seizure of the domains effectively disrupts the operation of this major DDoS-for-hire service, reducing the availability of such criminal infrastructure and potentially decreasing the frequency of related attacks. The coordinated international law enforcement efforts under Operation PowerOFF have also led to arrests and further dismantling of similar services, contributing to broader mitigation of DDoS threats.
Defensive Guidance
The FBI seizure of NightmareStresser domains and ongoing Operation PowerOFF enforcement actions have disrupted this DDoS-for-hire platform, effectively mitigating the threat it posed. No direct remediation actions are required by defenders specifically for this platform's takedown. Organizations should continue to implement standard DDoS protection measures as usual, but the removal of NightmareStresser reduces the availability of this particular criminal service. Monitoring law enforcement updates on Operation PowerOFF is recommended for awareness of further takedowns and arrests related to DDoS-for-hire services.
Technical Details
- Classification
- {"confidence":0.67,"severitySource":"default","classifier":"rss-v2"}
- Article Source
- {"url":"https://www.bleepingcomputer.com/news/security/fbi-seizes-nightmarestresser-service-linked-to-thousands-of-ddos-attacks/","fetched":true,"fetchedAt":"2026-09-17T12:31:58.893Z","wordCount":672}
Threat ID: 6aabddbe55bf5e2cf55fd4bb
Added to database: 09/17/2026, 12:31:58 UTC
Last enriched: 09/17/2026, 12:32:04 UTC
Last updated: 09/18/2026, 00:44:15 UTC
Views: 11
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.