"It's somewhat shocking that it's taken law enforcement this long to take action," Zach Edwards, a staff threat researcher at Infoblox, told CyberScoop.
Operation PowerOFF: a coordinated takedown
Authorities, acting as part of a globally coordinated effort called "Operation PowerOFF," seized the primary domain and other websites linked to NightmareStresser, one of the longest-running and most popular distributed denial-of-service (DDoS) operations used by cybercriminals worldwide, the Justice Department said. The seizures were executed by the FBI Anchorage field office and the Royal Canadian Mounted Police, and the former primary domain now displays a court-ordered seizure notice, officials said.
Scale: hundreds of thousands of attacks and tens of thousands of users
Officials said NightmareStresser was used to launch hundreds of thousands of DDoS attacks or attempted attacks since at least 2022. The service's operators, Edwards said, claimed tens of thousands of users. Authorities have previously seized more than 100 domains associated with DDoS-for-hire services since 2018, underscoring a sustained enforcement focus on so-called IP stressers or DDoS booters.

Nobody's watching your logs at 2 AM.
Full SOC coverage without building one. Nubivance deploys and manages Rapid7 InsightIDR and MDR for organizations that need detection and response, not another dashboard.
Get coverageWho was targeted: education, government, gaming, and "millions of people"
Authorities reported that customers of NightmareStresser targeted victims in the United States and abroad, including educational institutions, government agencies, gaming platforms, and “millions of people,” according to the Justice Department and comments relayed by Edwards to CyberScoop. Edwards said the vast majority of users are "script kiddies," frequently motivated by pranks or obscure political agendas, and that these services have been heavily used against gaming servers and streamers.
Attribution, prosecution, and limits of disruption
Officials did not name the operators of NightmareStresser or identify its country of origin. Edwards told CyberScoop that the service itself claimed to operate under the laws of the Russian Federation, and he warned that such a claim could make it difficult to bring operators to justice even if they were identified. He also cautioned that the impact of the seizure may be temporary: "These booter services are like playing a game of Whac-A-Mole," he said, noting that underground networks quickly shift to new providers when one is taken down.
What this means for technologists, law enforcement, and gaming platforms
- Technologists and security teams: The takedown removes a publicly visible access point and at least one high-profile infrastructure element—a domain now showing a seizure notice—but Edwards emphasized that DDoS-for-hire tools remain prolific and easily accessible, often accompanied by tutorials that enable non-technical users to launch attacks. Teams will need to remain vigilant for follow-on services and the migration of customers to other providers.
- Law enforcement and prosecutors: Authorities are likely to focus on identifying the operators, business partners, and users of NightmareStresser, officials and Edwards said. The claim that the service operated under Russian law complicates potential prosecution strategies and cross-border legal cooperation.
- Gaming platforms, streamers, and affected enterprises: Given that NightmareStresser’s customers frequently targeted gaming servers and streamers and that attacks hit education and government organizations as well, affected organizations should expect a continuing threat environment even after this seizure—mirroring the broader pattern of more than 100 domains seized since 2018 but persistent availability of similar services.
The seizure represents a concrete enforcement success: a public domain now displays a court-ordered seizure notice and a coordinated international operation removed a visible instance of a widely used DDoS-for-hire service. Yet the record presented by officials and the assessment from Edwards leave open two realities: that hundreds of thousands of attack attempts can be traced to a service that operated openly online, and that dismantling one domain does not necessarily eliminate the business model or the customers who fuel it. As law enforcement seeks operators and users, underground networks and non-technical attackers who relied on tutorials and affiliate programs will be the variables that decide whether this action produces sustained reduction in attacks or, as Edwards put it, simply prompts the next Whac-A-Mole.
Original story: https://cyberscoop.com/fbi-seizes-nightmarestresser-ddos-for-hire-domains/




