The US Federal Bureau of Investigation (FBI) has dealt a significant blow to cybercrime by taking down NightmareStresser, one of the world’s longest-running DDoS-for-hire platforms. This development marks another major victory for international law enforcement agencies in their ongoing efforts to dismantle malicious online services.
NightmareStresser was a platform that allowed anyone to rent large botnets of compromised routers and IoT devices to launch massive DDoS attacks targeting online platforms and services. The service boasted over 566,000 registered users and 52 dedicated servers capable of unleashing attacks of up to 200 Gbps on multiple layers of a network, including Layer 7 application protocols and Layer 4 TCP/UDP protocols.
DDoS-for-hire services like NightmareStresser have become increasingly popular among cybercriminals in recent years. These platforms offer a convenient way for attackers to launch powerful DDoS attacks without requiring extensive technical expertise. This can lead to significant disruptions for online services, causing downtime and financial losses for affected businesses.
The takedown of NightmareStresser is part of Operation PowerOFF, an ongoing international law enforcement effort that began in December 2018 with the seizure of 15 websites linked to DDoS-as-a-service platforms. Since then, this operation has led to the takedown of several other notable DDoS-for-hire services, including DigitalStress and Dstat.cc.
The FBI’s actions are a testament to the importance of international cooperation in combating cybercrime. By working together, law enforcement agencies can pool their resources and expertise to take down malicious online services that pose a threat to global cybersecurity. This development serves as a warning to other cybercriminals: even the most seemingly secure platforms can be taken down with sufficient effort.
As we continue to navigate the complex world of cybercrime, it’s essential for businesses and individuals to remain vigilant against DDoS attacks. By staying informed about emerging threats and taking proactive measures to protect their online presence, organizations can mitigate the risk of falling victim to these types of attacks.
In light of this development, cybersecurity professionals would do well to review their DDoS mitigation strategies and consider implementing additional safeguards to prevent or minimize the impact of future attacks. This includes staying up-to-date with the latest security patches, monitoring network traffic for suspicious activity, and having a clear incident response plan in place in case of an attack.
Source: Bleeping Computer — 2026-09-17