The U.S. Department of Justice, FBI Anchorage Field Office, and Royal Canadian Mounted Police seized court-authorized domains supporting NightmareStresser, a long-running DDoS-for-hire service. The action, conducted under the international Operation PowerOFF initiative, took the service offline after it had enabled hundreds of thousands of actual or attempted distributed denial-of-service attacks worldwide since 2022.
NightmareStresser allowed customers—often paying with cryptocurrency—to launch disruptive attacks without advanced technical skill. Its targets included educational institutions, government agencies, gaming platforms, and individual victims in the United States and other countries; organizations exposed to such services should maintain DDoS mitigation coverage, monitor for attack traffic, and preserve relevant evidence for law enforcement.

TTPs, infrastructure, and targeting history in one profile.
5 events from the most recent confirmed update back to the earliest known activity.
A coordinated Operation PowerOFF action across 21 countries took down 53 domains, arrested four operators, and sent warning letters to more than 75,000 identified platform users.
An Operation PowerOFF sweep disrupted 27 DDoS-for-hire, or booter, websites.
The U.S. Department of Justice previously seized nightmare-stresser[.]com as part of an enforcement action that seized 48 domains associated with DDoS-for-hire services.
According to a seizure-warrant affidavit, NightmareStresser was used to conduct hundreds of thousands of actual or attempted DDoS attacks against victims worldwide beginning in 2022.
The FBI Anchorage Field Office, assisted by the Royal Canadian Mounted Police Federal Policing Northwest Region, seized court-authorized domains associated with the NightmareStresser DDoS-for-hire service under Operation PowerOFF. The action disrupted infrastructure used to let paying customers launch attacks against targets in Alaska, the United States, and worldwide.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
5 references tracked. Mallory keeps watching after this page renders.
cyberscoop.com
Open sourcehelpnetsecurity.com
Open sourcesecurityaffairs.com
Open sourcethehackernews.com
Open sourcejustice.gov
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.