515/69 Friday, September 18, 2026

The U.S. Federal Bureau of Investigation (FBI), in cooperation with the Royal Canadian Mounted Police (RCMP), has seized internet domains associated with NightmareStresser, a DDoS-for-hire service accused of allowing customers to pay for access to infrastructure used to attack targets worldwide. The U.S. Department of Justice stated that NightmareStresser had been operating since 2022 and was one of the long-running Distributed Denial-of-Service (DDoS) rental services. According to information in the domain seizure warrant application, the service was used to conduct or attempt hundreds of thousands of DDoS attacks against victims globally.
DDoS-for-hire services, often referred to as booters or stressers, are platforms that allow customers to use attack infrastructure to send large volumes of traffic to websites, servers, or internet-connected systems, causing services to slow down, become unavailable, or experience connection disruption. Customers do not need to build their own botnets or attack infrastructure, but can pay through online services or cryptocurrency to launch attacks against selected targets. The U.S. Department of Justice stated that such services have been used to attack educational institutions, government agencies, gaming platforms, and other victims both in the United States and abroad. However, in the case of NightmareStresser, authorities did not disclose the names of target organizations or customers who used the service.
The domain seizure placed NightmareStresser-related domains under the control of law enforcement, and visitors to the infrastructure will see a law enforcement notice instead of the original content. No arrests or charges against NightmareStresser administrators have been announced in connection with the domain seizure. The operation is part of Operation PowerOFF, an international effort to disrupt DDoS-for-hire infrastructure and those involved. In previous actions, U.S. law enforcement and partner agencies have targeted similar services multiple times, including the seizure of more than 100 domains over the past eight years, as well as operations involving agencies from multiple countries, including Europol, the United Kingdom, Germany, the Netherlands, Poland, Japan, and France. Private-sector organizations such as Akamai, Amazon Web Services, Cloudflare, Google, PayPal, and the Shadowserver Foundation have also provided assistance.
Source: https://hackread.com/operation-poweroff-nightmarestresser-ddos-for-hire-domains-seized/
