threat_intelligence822 wordsRead on Arc Codex

NightmareStresser Goes Offline in Global DDoS

Renting a DDoS attack used to be as easy as renting a movie. Pick a target, pay a few dollars, watch the site go dark. The Justice Department just made that a little harder by seizing the domains behind NightmareStresser, one of the longest-running services in that business. “The Justice Department today announced the court-authorized seizure of internet domains associated with one of the world’s longest running Distributed Denial of Service (DDoS) for-hire services known as “NightmareStresser.” ” states DoJ. “Federal law enforcement has seized websites maintained by criminal service providers that allow paying customers to launch powerful DDoS attacks targeting victims in the District of Alaska and worldwide as part of coordinated actions to disrupt so called “Booter” or “Stresser” operators.” The announcement came from the District of Alaska, which may seem like an unusual place for a DDoS takedown. But Anchorage prosecutors have been investigating and fighting DDoS-for-hire services for almost a decade. Federal authorities seized the websites under a court-approved warrant, preventing customers from using the service to launch attacks against targets in Alaska and around the world. These services are often called “booters” or “stressers,” names that make renting a DDoS attack sound like a simple online service. It’s tempting to file DDoS attacks under “annoying but harmless.” The DOJ’s own description of the victim pool argues otherwise. “Booter services such as those named in this action allegedly facilitate attacks on a wide array of victims in the United States and abroad, including educational institutions, government agencies, gaming platforms and millions of people. In addition to affecting targeted victims, these attacks can significantly degrade internet services and can completely disrupt internet connections.” continues DoJ. “According to the seizure warrant affidavit, the NightmareStresser Booter service targeted in this operation was used to launch hundreds of thousands of actual or attempted DDoS attacks targeting victims worldwide since 2022. “ A school district losing internet access during exam week, a city government portal going dark, a gaming server getting flooded mid-match: none of that is abstract to the people dealing with it in the moment. These attacks can slow down internet services or completely take them offline. The impact can also go beyond the main target, affecting other users and services that rely on the same network infrastructure. NightmareStresser wasn’t a small operation running a handful of scripts for hobbyists. “According to the seizure warrant affidavit, the NightmareStresser Booter service targeted in this operation was used to launch hundreds of thousands of actual or attempted DDoS attacks targeting victims worldwide since 2022.” states DoJ. That’s over three years of near-continuous rental attacks, on a service that markets itself with a name straight out of a horror movie. The FBI’s Anchorage Field Office ran the technical side with help from the Royal Canadian Mounted Police’s Federal Policing Northwest Region. It’s a reminder that DDoS-for-hire crime doesn’t respect borders, so neither does the response to it. This seizure sits inside Operation PowerOFF, the ongoing international campaign that’s been dismantling DDoS-for-hire infrastructure and going after the people running it for years. Just this past April, a coordinated action across 21 countries took down 53 domains, arrested four operators, and sent warning letters to more than 75,000 identified users of these platforms. Before that, in December 2024, another PowerOFF sweep knocked out 27 booter sites in one go. Alaska’s own contribution to that broader effort goes back further than most people would guess. “In previous law enforcement actions involving prosecutors and investigators in Anchorage and Los Angeles over the last eight years, the Justice Department charged twelve defendants who facilitated DDoS-for hire services and seized more than 100 internet domains associated with DDoS-for-hire services.” continues DoJ. “The multi-prong investigation announced today builds on the success of the prior cases by targeting all known booter sites, shutting down as many as possible, and undertaking a public education campaign.” Twelve people and a hundred domains later, they’re still finding new ones to shut down. Booter services are difficult to eliminate completely. When one is taken down, another can quickly appear, often using similar business models. The DOJ says these services have continued to grow because they make it easy for people with little technical knowledge to launch DDoS attacks. Users don’t need to write code or understand how networks work. They can simply visit a website, pay for the service, often using cryptocurrency, and choose their target. This low barrier to entry has made DDoS-for-hire services accessible to a much wider group of cybercriminals. Assistant U.S. Attorneys Adam Alexander and Ainsley McNerney are prosecuting the case out of the District of Alaska. The DOJ was explicit that this investigation isn’t a one-off strike but part of a wider plan to target every known booter site it can find, shut down as many as possible, and keep running public education alongside the legal action. Follow me on Twitter: @securityaffairs and Facebook and Mastodon (SecurityAffairs – hacking, Operation PowerOFF)

How it works

Once you click Generate, Ollama reads this article and crafts 5 comprehension questions. Your answers are graded against the article content — general knowledge won't be enough. Score 70+ to count toward your certificate.

Questions are cached — you'll always get the same 5 for this article.