"This domain has been seized by the Federal Bureau of Investigation in accordance with a seizure warrant pursuant to 18 U.S.C. §§ 981(a)(1)(A) and (b), 982(b)(1), and 1030(i) (1)(A); and 21 U.S.C. § 853 issued by the United States District Court for the District of Alaska," reads the seizure banner now posted on nightmare-stresser[.]com and nightmarestresser[.]org.
The domains seized and the legal authorities invoked
The U.S. Department of Justice announced a court-authorized seizure of the two internet domains tied to a DDoS-for-hire service known as NightmareStresser. The seizure banner—posted to visitors of nightmare-stresser[.]com and nightmarestresser[.]org—names the Federal Bureau of Investigation and cites specific statutes and the United States District Court for the District of Alaska as the legal basis. The action was carried out as part of a joint international operation involving the United States Attorney's Office for the District of Alaska, the FBI Anchorage Field Office, and the Royal Canadian Mounted Police (RCMP).
NightmareStresser: scale, claims, and commercial features
According to the Justice Department, NightmareStresser has been used to launch "hundreds of thousands of actual or attempted DDoS attacks against victims across the world since 2022." The service marketed itself as a 24x7 DDoS tool, claiming on its now-taken-down website to be "the only DDoS tool available 24x7, running non-stop for over 8 years." The site also offered features and claims that read like a product brochure for malicious actors: advanced Layer 4 amplification, Layer 4 bypasses over UDP/TCP, Layer 7 methods that it said could defeat CAPTCHAs, geoblocks, and rate limits, and a one-click "Stop All" control to halt active floods.
Searchlight Cyber reported in late 2023 that NightmareStresser had more than 566,000 registered users and 52 servers. The platform reportedly allowed customers to pick target IPs or URLs, choose port numbers, and select the number of concurrent attacks. The site accepted cryptocurrency payments and ran an "advanced referral system" that awarded credit when referral links were used to visit the site, a mechanism that permanently linked referred users to referrers for future credit.

Nobody's watching your logs at 2 AM.
Full SOC coverage without building one. Nubivance deploys and manages Rapid7 InsightIDR and MDR for organizations that need detection and response, not another dashboard.
Get coverageTechnical footprint noted in public records
Snapshots captured by the Internet Archive indicate that the nightmarestresser[.]org domain was protected against DDoS itself by a web infrastructure provider identified as BlazingFast. The public descriptions of the service’s features—Layer 4 amplification, Layer 7 bypasses, and a centralized control for stopping floods—underscore why the Justice Department describes booter services as both commercially structured and operationally capable of large-scale disruption: "In addition to affecting targeted victims, these attacks can significantly degrade internet services and can completely disrupt internet connections," the DoJ said.
Operation PowerOFF and the broader enforcement campaign
The seizure is part of Operation PowerOFF, a coordinated law enforcement initiative to dismantle commercial DDoS-for-hire infrastructures worldwide. The DoJ noted this action builds on earlier steps: in December 2022 one NightmareStresser domain was among 48 domains seized; an April operation disrupted 53 domains and resulted in the arrest of four people; and, collectively, twelve defendants have been charged in cases tied to DDoS-for-hire services while more than 100 internet domains linked to such services have been seized.
What this means for educational institutions, gaming platforms, and security teams
- Educational institutions and government agencies: These sectors were explicitly cited as targets of booter attacks. The public seizures remove specific public-facing infrastructure used to coordinate attacks, potentially reducing one readily available avenue for disruption, but they do not by themselves eliminate the underlying methods or all possible platforms used to launch attacks.
- Gaming platforms: The DoJ named gaming platforms among targeted sectors. Platform operators will likely track whether referral-linked customers and cryptocurrency payment channels tied to NightmareStresser cease to operate and whether demand shifts to other commercial DDoS services.
- Security teams and ISPs: With NightmareStresser assessed to have furnished hundreds of thousands of attempted attacks, network defenders should note the scale and automated features reported—such as target selection, concurrent attack controls, and amplification techniques—when tuning mitigation, capacity planning, and incident response playbooks.
The takedown is emphatically procedural and public: the DoJ described the effort as "multi-prong," aiming not only to shut down known booter sites but also to undertake a public education campaign. That is a concrete next step, but it leaves a practical question visible in the docket of prior actions: can enforcement and education keep pace with services that advertise ease of use, cryptocurrency payment, and referral-driven growth? The seizure removes two prominent domains and adds to a tally of more than 100 domains seized and a dozen defendants charged, but the operational effects—on attack volumes, user behavior, and the ecosystem’s resilience—will be revealed only in the weeks and months ahead.




