On Tuesday, the U.S. Federal Bureau of Investigation (FBI) seized the domains used by NightmareStresser, one of the world's longest-running distributed denial-of-service (DDoS) platforms.
"Booter services" like NightmareStresser are DDoS-for-hire services that let anyone rent large botnets of compromised routers and a wide range of IoT devices to launch massive DDoS attacks targeting online platforms and services.
Before the nightmare-stresser[.]com and nightmarestresser[.]org were taken down, the stresser service described itself as the "#1 online IP booter" and "the only DDoS tool available 24/7."
As cybersecurity firm Searchlight Cyber reported in 2023, NightmareStresser had over 566,000 registered users and 52 dedicated servers that could launch DDoS attacks of up to 200 Gbps targeting multiple layers of a network (including Layer 7 application protocols and Layer 4 TCP/UDP protocols).
"Since 2022, the NightmareStresser Booter service was used to launch hundreds of thousands of actual or attempted DDoS attacks targeting victims worldwide," the FBI Cyber Division said on Wednesday.
"This enforcement action was supported by Operation PowerOFF, a coordinated effort among international law enforcement agencies aimed at dismantling criminal D DoS-for-hire infrastructures worldwide," a seizure banner now displayed on the seized domains reads.
NightmareStresser seizure banner (BleepingComputer)
In December 2022, the U.S. Department of Justice (DOJ) also took down the nightmarestresser[.]com domain and arrested six suspects who allegedly owned multiple DDoS-for-hire services.
Operation PowerOFF is an ongoing, long-running joint law enforcement action that began in December 2018 with the seizure of 15 websites linked to DDoS-as-a-service platforms.
Previously, this operation has led to the takedown of the DigitalStress DDoS-for-hire service in the United Kingdom, the seizure of the Dstat.cc DDoS review platform, and the arrest of two stresser service operators in Poland.
... continue reading