"Since 2022, the NightmareStresser Booter service was used to launch hundreds of thousands of actual or attempted DDoS attacks targeting victims worldwide," the FBI Cyber Division said on Wednesday.
FBI seizure of nightmare-stresser[.]com and nightmarestresser[.]org
On Tuesday the Federal Bureau of Investigation seized the domains used by NightmareStresser, one of the longest-running distributed denial-of-service (DDoS) for-hire platforms. A seizure banner now displayed on the two domains states the enforcement action was supported by Operation PowerOFF, describing the effort as a coordinated international law enforcement campaign aimed at dismantling criminal DDoS-for-hire infrastructures worldwide.
How NightmareStresser presented itself and who it reached
Before the domains were taken down, NightmareStresser's stresser service described itself as the "#1 online IP booter" and "the only DDoS tool available 24/7." As cybersecurity firm Searchlight Cyber documented in 2023, the platform had more than 566,000 registered users and ran 52 dedicated servers. Those servers were capable of launching attacks of up to 200 Gbps against multiple network layers, including Layer 7 application protocols and Layer 4 TCP/UDP protocols.

The cyber insurance questionnaire just landed. Now what?
SOC 2, HIPAA, insurance renewals - someone has to own security strategy. Nubivance provides fractional CISO leadership without the full-time salary.
Get a security leadHow the service operated: booters, botnets, and compromised devices
NightmareStresser was one of a class of so‑called "booter services" that let individuals rent access to large botnets of compromised routers and a wide range of Internet‑connected devices to mount DDoS attacks. The FBI described those services as DDoS‑for‑hire platforms that enable customers to attempt large, often automated, denial‑of‑service campaigns against online platforms and services. The bureau's public statement highlights the scale of real‑world impact: hundreds of thousands of actual or attempted attacks since 2022.
Operation PowerOFF and the international enforcement record
The seizure of the NightmareStresser domains is part of Operation PowerOFF, a long‑running, international enforcement effort that dates back to December 2018, when authorities seized 15 websites tied to DDoS-as-a-service platforms. The operation has previously produced multiple takedowns and arrests: law enforcement in the United Kingdom dismantled the DigitalStress DDoS-for-hire service; the Dstat.cc DDoS review platform was seized; two stresser service operators were arrested in Poland; and, in separate waves, authorities seized 13 domains and then 48 additional domains hosting booter platforms.
In December 2022 the U.S. Department of Justice seized the nightmarestresser[.]com domain and arrested six suspects who were alleged to own multiple DDoS‑for‑hire services. Last year, Polish authorities detained four suspects linked to six platforms that were tied to thousands of attacks against schools, government services, businesses, and gaming platforms; the United States seized nine domains in that coordinated crackdown.
What this means for technologists, policymakers, and end users
- Technologists and security teams: Expect continued enforcement‑driven disruption of specific domains and services, but also the persistence of the underlying problem—large botnets built from compromised routers and IoT devices that can be rented to launch attacks at up to 200 Gbps and across Layers 4 and 7. Monitoring for reuse of seized infrastructure and for new booter offerings remains necessary.
- Policymakers and law enforcement: The action reinforces that Operation PowerOFF is an ongoing, multiyear international campaign stretching back to December 2018 and involving coordinated seizures and arrests across multiple countries. The seizure of NightmareStresser underscores the cross‑border nature of DDoS‑for‑hire networks and the sustained effort required to dismantle them.
- End users and the general public: The public dimension is straightforward in the FBI's description—the botnets used by these services are composed of compromised routers and a wide range of IoT devices. Devices on homes and small networks can be co‑opted into large attack fleets that are then rented out to launch disruptive traffic floods against third‑party targets.
The seizure of nightmare-stresser[.]com and nightmarestresser[.]org is another chapter in a multi‑year, multinational campaign to interrupt the DDoS‑for‑hire market. The enforcement record cited by authorities — domain seizures, platform takedowns, and arrests across several countries — shows sustained pressure but also illustrates the repeated nature of this work: platforms rise, law enforcement moves, and other infrastructure often follows. For now, the FBI says NightmareStresser was responsible for hundreds of thousands of attacks or attempts since 2022, and Operation PowerOFF continues to be the vehicle through which those disruptions are pursued.




