Skip to main content
Mallory
Back to intelligence
enforcement-actioncybercrime-service-ecosystembotnet-infrastructuresearch-ad-manipulation

Operation PowerOFF disrupts DDoS-for-hire platforms and arrests administrators

Updated 12d agoFirst seen May 25, 20266 sources

An international law enforcement campaign under Operation PowerOFF has repeatedly dismantled major DDoS-for-hire or booter/stresser services, seizing domains and infrastructure, arresting alleged administrators, and targeting customers across dozens of countries. In one major phase, authorities shut down 48 services and arrested seven suspected operators after U.S. charges tied defendants to platforms including Booter.sx, Astrostress.com, and SecurityTeam.io; officials said one seized service alone had been used in more than 30 million attacks. A later coordinated action involving the United States and about 20 partner countries seized 53 domains, made four arrests, executed 25 search warrants, and sent more than 75,000 warning messages to users, while also removing more than 100 URLs advertising booter sites.

The crackdown builds on earlier takedowns such as the seizure of Webstresser.org, which Europol described as the world’s largest DDoS-for-hire marketplace, with more than 136,000 registered users and 4 million attacks recorded before it was dismantled. Investigators said these services marketed themselves as legitimate network testing tools but were used to launch attacks against schools, government agencies, gaming platforms, critical infrastructure, Department of Defense resources, businesses, and individuals, often for as little as EUR 15 per month. Authorities also expanded disruption efforts beyond arrests and seizures by placing warning ads in search results and reaching users through cryptocurrency payment channels, underscoring a sustained multinational effort to raise the cost of operating and buying low-barrier DDoS attack services.

Share:
Operation PowerOFF disrupts DDoS-for-hire platforms and arrests administrators
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

5 events from the most recent confirmed update back to the earliest known activity.

5 EVENTS
Apr 13, 20262mo ago

Operation PowerOFF seizes 53 domains and makes four arrests

In April 2026, the United States and 20 partner countries carried out a coordinated Operation PowerOFF action that seized 53 domains tied to booter services, made four arrests, and executed 25 search warrants. Authorities also sent more than 75,000 warning messages to customers and removed more than 100 URLs advertising the services.

Dec 12, 20241y ago

Operation PowerOFF disrupts 27 DDoS platforms across 15 countries

In December 2024, an international crackdown under Operation PowerOFF took down 27 DDoS-for-hire platforms across 15 countries. The action marked a renewed multinational effort against booter services.

Dec 9, 20223y ago

Operation Power Off shuts down 48 DDoS-for-hire services and arrests seven

In December 2022, Europol announced an international operation that shut down 48 DDoS-for-hire websites and led to the arrest of seven alleged administrators, including one suspect in the United Kingdom. Authorities said one seized service had been used to conduct more than 30 million attacks against schools, government agencies, gaming platforms, and individuals.

U.S. charges six defendants tied to booter services

Before the December 2022 enforcement action, the U.S. Department of Justice charged six defendants linked to DDoS-for-hire services including Booter.sx, Astrostress.com, and SecurityTeam.io. The charges formed part of a broader crackdown on services marketed as network testing tools but used to launch attacks.

Apr 24, 20188y ago

Operation Power Off takes down Webstresser and arrests administrators

On 2018-04-24, law enforcement arrested the administrators of Webstresser.org, described by Europol as the world's largest DDoS-for-hire marketplace. Authorities shut down the service and seized infrastructure in the Netherlands, the United States, and Germany as part of Operation Power Off.

The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.

Operation PowerOFF disrupts DDoS-for-hire platforms and arrests administrators | Mallory