Another major operation against the market DDoS-for-hire was carried out by US authorities, with the FBI proceeding to seize the internet domains associated with NightmareStresser, one of the longest-running “booter” services in the world. The operation took place on Tuesday, September 15, and is part of the international Operation PowerOFF, a multi-year effort to dismantle infrastructures that offer DDoS attacks for a fee.

The seized websites now display a message from US authorities, and the operation was carried out by the FBI Anchorage Field Office in collaboration with the Royal Canadian Mounted Police. According to the US Department of Justice, the service had been used since 2022 for hundreds of thousands of actual or attempted attacks against targets around the world.
What are DDoS-for-hire services?
Platforms like NightmareStresser essentially operate as “for-hire” cyberattack services. Instead of someone having to build their own infrastructure for a DDoS attack, they can access already available resources and use them against an online target.
See also: FamousSparrow: SparroWocky backdoor targets government organizations
This model significantly lowers the technical barrier to attack. These services can leverage large networks of compromised devices, such as routers and IoT equipment, to generate a huge volume of requests to a target.
The result can be a degradation or complete disruption of an online service, affecting businesses, educational institutions, government agencies, gaming platforms and other infrastructure. The DOJ notes that such services have become an easily accessible mechanism for those who want to cause internet outages.
The size of NightmareStresser
Before the seizure of the domains nightmare-stresser.com and nightmarestresser.org, NightmareStresser was advertised as a tool that could be available 24/7.
Previously disclosed data showed the platform's size, with more than 566,000 registered users and dozens of dedicated servers. Its infrastructure could reportedly be used for large-scale attacks, targeting different layers of a network.
The assessment of the American authorities is even more indicative: the service has been linked to hundreds of thousands attackssince 2022, which demonstrates that the problem was not limited to isolated incidents.

Operation PowerOFF continues international pressure
The seizure of NightmareStresser is part of Operation PowerOFF, an international and ongoing effort targeting DDoS-for-hire providers, as well as those who operate or use illegal “booter” and “stresser” services.
The FBI says the operation relies on the cooperation of multiple law enforcement agencies and has led to previous domain seizures, arrests, and shutdowns of relevant platforms.
See also: OpenAI: AI agents allegedly “mapped” Hugging Face before July attack
The DOJ says that in previous cases related to investigations by authorities in Alaska and Los Angeles, 12 people were charged and more than 100 domains related to DDoS-for-hire services were seized
Why authorities are targeting infrastructure
Seizing domains is not just a symbolic gesture. For services that rely on centralized web infrastructure, removing key domains can disrupt customer access and make it more difficult for the platform to operate.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
At the same time, authorities are trying to increase the costs for the operators of such services. The more platforms collapse and the more users are identified, the harder it becomes for this business model to operate with the same ease.
The challenge, of course, remains significant. The DDoS-for-hire market has shown that it can adapt quickly, with new websites and infrastructure popping up as older services shut down.

The threat to businesses and organizations
For a business, even a brief DDoS attack can have financial and operational consequences. An outage of a website or online service can mean lost transactions, customer access issues , and additional restoration costs.
That's why the response is not limited to authorities. Organizations need to have DDoS mitigation, network traffic monitoring, incident response plans, and collaboration with infrastructure providers.
See also: N0va Phishkit targets businesses in the US and EU
The NightmareStresser case is a reminder, ultimately, that cyberattacks do not always require a high level of technical knowledge from the perpetrator. The existence of services that offer ready access to offensive capabilities has turned DDoS into a more accessible cybercrime tool.
The FBI's new seizure is yet another blow to this market, but Operation PowerOFF shows that the fight against DDoS-for-hire platforms is a long-term one and requires ongoing international cooperation, technical monitoring, and coordinated operations.
source: bleepingcomputer.com
