The U.S. Federal Bureau of Investigation (FBI) has seized the domains used by NightmareStresser, one of the longest-running distributed denial-of-service (DDoS) platforms.
NightmareStresser operated as a DDoS-for-hire service, also known as a booter service, allowing users to rent access to large botnets made up of compromised routers and IoT devices to launch DDoS attacks against online platforms and services.
Before the domains nightmare-stresser[.]com and nightmarestresser[.]org were taken down, the service described itself as the “#1 online IP booter” and claimed to be the only DDoS tool available 24/7.
According to cybersecurity firm Searchlight Cyber, NightmareStresser had more than 566,000 registered users and operated 52 dedicated servers capable of launching attacks of up to 200 Gbps. The platform could target multiple layers of a network, including Layer 7 application protocols and Layer 4 TCP/UDP protocols.
The FBI and DOJ are announcing the seizure of internet domains associated with NightmareStresser, one of the world’s longest running Distributed Denial of Service (DDoS) for-hire services. Since 2022, the NightmareStresser Booter service was used to launch hundreds of thousands… pic.twitter.com/cT7HMKhs9G
— FBI Cyber Division (@FBICyberDiv) September 16, 2026
The FBI Cyber Division said that since 2022, the NightmareStresser service had been used to launch hundreds of thousands of actual or attempted DDoS attacks against victims around the world.
A seizure banner displayed on the domains says the enforcement action was supported by Operation PowerOFF, an international law enforcement effort focused on dismantling DDoS-for-hire infrastructure.
The latest action follows an earlier takedown of the nightmare-stresser[.]com domain by the U.S. Department of Justice in December 2022. At the time, authorities arrested six suspects who were allegedly operating multiple DDoS-for-hire services.
Operation PowerOFF began in December 2018 with the seizure of 15 websites linked to DDoS-as-a-service platforms. Since then, the operation has targeted several other services and operators involved in DDoS-for-hire activity.
Previous actions have included the takedown of the DigitalStress DDoS-for-hire service in the United Kingdom, the seizure of the Dstat.cc DDoS review platform and the arrest of two stresser service operators in Poland.
Authorities have also seized 13 domains in one enforcement wave and another 48 domains in a separate operation targeting booter platforms.
If this article helped you, please consider supporting our work. Every small contribution keeps Abijita.com independent and running.
Last year, Polish authorities detained four suspects linked to six DDoS-for-hire platforms that were allegedly behind thousands of attacks targeting schools, government services, businesses and gaming platforms worldwide since 2022. In the same coordinated crackdown, U.S. authorities also seized nine domains linked to DDoS-for-hire services.



