US takes down NightmareStresser DDoS
On Tuesday, the U.S. Federal Bureau of Investigation (FBI) seized the domains used by NightmareStresser, one of the world's longest-running distributed denial-of-service (DDoS) platforms.
"Booter services" like NightmareStresser are DDoS-for-hire services that let anyone rent large botnets of compromised routers and a wide range of IoT devices to launch massive DDoS attacks targeting online platforms and services.
Before the nightmare-stresser[.]com and nightmarestresser[.]org were taken down, the stresser service described itself as the "#1 online IP booter" and "the only DDoS tool available 24/7."
As cybersecurity firm Searchlight Cyber reported in 2023, NightmareStresser had over 566,000 registered users and 52 dedicated servers that could launch DDoS attacks of up to 200 Gbps targeting multiple layers of a network (including Layer 7 application protocols and Layer 4 TCP/UDP protocols).
"Since 2022, the NightmareStresser Booter service was used to launch hundreds of thousands of actual or attempted DDoS attacks targeting victims worldwide," the FBI Cyber Division said on Wednesday.
"This enforcement action was supported by Operation PowerOFF, a coordinated effort among international law enforcement agencies aimed at dismantling criminal D DoS-for-hire infrastructures worldwide," a seizure banner now displayed on the seized domains reads.
In December 2022, the U.S. Department of Justice (DOJ) also took down the nightmarestresser[.]com domain and arrested six suspects who allegedly owned multiple DDoS-for-hire services.
Operation PowerOFF is an ongoing, long-running joint law enforcement action that began in December 2018 with the seizure of 15 websites linked to DDoS-as-a-service platforms.
Previously, this operation has led to the takedown of the DigitalStress DDoS-for-hire service in the United Kingdom, the seizure of the Dstat.cc DDoS review platform, and the arrest of two stresser service operators in Poland.
In other joint actions under Operation PowerOFF, law enforcement seized 13 domains and 48 more domains hosting booter platforms in two separate enforcement waves.
Last year, Polish authorities also detained four suspects linked to six DDoS-for-hire platforms behind thousands of attacks targeting schools, government services, businesses, and gaming platforms worldwide since 2022, while the U.S. seized nine domains in the same coordinated crackdown on DDoS services.
Build your security blueprint for AI-powered attacks
Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.
Save your seat
Post a Comment Community Rules
You need to login in order to post a comment
Not a member yet? Register Now
How it works
Once you click Generate, Ollama reads this article and crafts 5 comprehension questions. Your answers are graded against the article content — general knowledge won't be enough. Score 70+ to count toward your certificate.
Questions are cached — you'll always get the same 5 for this article.