The NightmareStresser DDoS Service Has Been Disrupted in a Major International Operation
In a significant blow to cybercrime, authorities have disrupted one of the world’s longest-running distributed denial-of-service (DDoS) for-hire services, NightmareStresser. The US Department of Justice announced this week that the FBI has seized the internet domains associated with the booter service, effectively putting an end to its operations.
NightmareStresser had been active since at least 2022 and was used to launch hundreds of thousands of DDoS attacks against victims worldwide. According to security researcher Alex Carter, who investigated the service last year, NightmareStresser likely originated in 2016 and became popular in 2018 after rival services were disrupted. By 2025, it had grown to nearly 1 million users and could launch between 3,000 and 4,000 attacks per hour.
The disruption of NightmareStresser was part of Operation PowerOFF, a coordinated global effort to dismantle DDoS-for-hire infrastructures globally and hold the individuals behind these services accountable. This operation is just the latest in a series of efforts by law enforcement agencies to combat the proliferation of DDoS-for-hire services.
DDoS-for-hire services, also known as booters or stressers, have been proliferating over the past years due to their low-entry barriers for cybercriminal-wannabes. These services allow individuals to rent access to powerful botnets and launch large-scale attacks against their victims. The US has charged 12 DDoS attack facilitators in recent years and seized over 100 domains associated with booter services.
In addition to disrupting DDoS-for-hire infrastructure, law enforcement agencies have been tracking and charging both the administrators and the users of these services. This approach is crucial in addressing the issue, as it not only disrupts the services but also holds accountable those who use them.
The NightmareStresser disruption is a significant development in the ongoing battle against cybercrime. It sends a strong message to would-be attackers that their activities will be tracked and disrupted. However, it’s essential for individuals and organizations to remain vigilant and take proactive measures to protect themselves from DDoS attacks.
To avoid falling victim to DDoS attacks, individuals and organizations should focus on implementing robust security measures, such as:
* Monitoring network traffic for suspicious activity
* Implementing robust firewalls and intrusion detection systems
* Conducting regular security audits and penetration testing
* Educating employees about cybersecurity best practices
By staying informed and taking proactive steps to protect themselves, individuals and organizations can reduce their risk of falling victim to DDoS attacks. The disruption of NightmareStresser is a significant step forward in the fight against cybercrime, but it’s only one part of a larger effort to keep our digital world safe and secure.
Source: SecurityWeek — 2026-09-18