U.S. seizes NightmareStresser DDoS‑for‑hire domains after hundreds of thousands of attacks since 2022
U.S. authorities have taken control of two domains linked to NightmareStresser, a DDoS‑for‑hire platform assessed to have been used in hundreds of thousands of attacks and attempts worldwide since 2022. The seizure, part of Operation PowerOFF, targets a service that let paying users overwhelm websites and networks with traffic.
Two domains tied to the NightmareStresser service have been seized by U.S. authorities, in a move aimed at disrupting a platform linked to a huge number of rented cyberattacks.
According to reporting on Operation PowerOFF, investigators assessed that NightmareStresser had been used globally since 2022 in hundreds of thousands of distributed‑denial‑of‑service (DDoS) attacks and attempts. DDoS attacks overwhelm websites, servers or networks with traffic, making them unavailable to legitimate users.
NightmareStresser was marketed as a so‑called DDoS‑for‑hire or “stresser” service. Such platforms typically claim to offer tools for testing how well a network can withstand high traffic loads. In practice, they’re often used to knock other people’s sites or services offline.
By seizing the two domains associated with NightmareStresser, U.S. agencies have cut off key public access points to the service. The action doesn’t necessarily remove all of the underlying infrastructure, but it makes it harder for customers to find and buy access and serves as a warning that this kind of paid attack service is under active scrutiny.
The NightmareStresser case is part of Operation PowerOFF, a broader law‑enforcement effort targeting DDoS‑for‑hire services. Authorities frame these takedowns as a way to tackle not just individual attackers but the commercial platforms that make large‑scale disruption easy to buy.
What will show whether this seizure has lasting impact is how quickly replacement domains or copycat services appear, whether there are follow‑up actions against related infrastructure, and whether incident reports from network operators show any change in the volume of DDoS attacks traced to such rental platforms.
Sources
- OSINT