The FBI just pulled the plug on one of cybercrime’s oldest business models. On September 15, agents seized two domains, nightmare-stresser[.]com and nightmarestresser[.]org, tied to NightmareStresser, a distributed denial-of-service platform authorities call one of the longest-running booter services ever to operate online.
The scale of what got shut down is staggering. According to a seizure-warrant affidavit cited by the Justice Department, NightmareStresser had launched hundreds of thousands of actual or attempted DDoS attacks against victims worldwide since 2022. A 2023 investigation by Searchlight Cyber found the platform running more than 566,000 registered users off 52 dedicated servers, with an advertised attack capacity of up to 200 Gbps. It marketed itself, without irony, as the “#1 online IP booter.”
Booter services work like a twisted rental business. Instead of writing malware or building a botnet from scratch, a paying customer just logs in and points a rented flood of malicious traffic at whatever target they want knocked offline. NightmareStresser reportedly ran 3,000 to 4,000 attacks per hour, took cryptocurrency payments, and deliberately steered clear of government, education, and hospital domains, a strange sliver of self-preservation baked into an otherwise indiscriminate criminal service.
That self-imposed restraint didn’t stop the damage elsewhere. The Justice Department says booter attacks like this have hit educational institutions, government agencies, gaming platforms, and millions of ordinary users globally, flooding bandwidth until legitimate traffic simply can’t get through.
This isn’t NightmareStresser’s first brush with federal law enforcement. Back in December 2022, the DOJ seized 48 booter-service domains in one sweep, nightmare-stresser.com among them, and arrested six suspects tied to multiple DDoS-for-hire operations. The platform apparently rebuilt and kept running anyway, which is exactly the pattern investigators are now racing to break.
The FBI’s Anchorage Field Office ran this latest operation alongside the Royal Canadian Mounted Police’s Federal Policing Northwest Region. It falls under Operation PowerOFF, a continuing international campaign that’s been dismantling DDoS-for-hire infrastructure since December 2018, when the first coordinated wave took down 15 linked websites. Since then, related investigations out of Anchorage and Los Angeles have produced charges against 12 defendants and the seizure of more than 100 domains.
Notably, this specific announcement stayed quiet on arrests or new charges tied to the NightmareStresser seizure itself. Prosecutors Adam Alexander and Ainsley McNerney are handling the case, but the public record so far only confirms the infrastructure takedown, not who was running it or whether anyone’s been detained.
Security researchers are candid about what a domain seizure does and doesn’t accomplish. Taking NightmareStresser’s domains offline disrupts one major access point, but it doesn’t erase the wider DDoS-for-hire ecosystem, and operators can often rebuild on new infrastructure elsewhere. What the takedown does raise is the cost and risk of staying in that business, while preserving evidence that could still surface in future prosecutions.
Get instant alerts and updates based on your interests. Be the first to know when big stories happen.
There’s a warning buried in this for regular internet users too. Compromised routers, IoT devices, and home computers can quietly become part of the infrastructure powering these attacks, without their owners ever realizing their hardware has been drafted into someone else’s crime.
For anyone who treated a booter subscription as a low-stakes prank tool, this seizure carries a blunt message: that account may now be evidence, and prosecution under the Computer Fraud and Abuse Act carries real prison time and fines attached to it.





