The FBI seized the domains used by NightmareStresser, one of the longest-running distributed denial-of-service platforms in the world, on Tuesday. The takedown targeted the booter service's nightmare-stresser[.]com and nightmarestresser[.]org addresses, which now display a seizure banner. Booter services such as NightmareStresser rent out large networks of compromised routers and IoT devices so customers can launch DDoS attacks against online platforms and services.

Before it was taken offline, NightmareStresser marketed itself as the number one online IP booter and the only DDoS tool available around the clock. According to the cybersecurity firm Searchlight Cyber, which reported on the service in 2023, NightmareStresser had more than 566,000 registered users and 52 dedicated servers. Those servers were capable of launching attacks reaching up to 200 Gbps and could target multiple layers of a network, including Layer 7 application protocols and Layer 4 TCP and UDP protocols.

The FBI Cyber Division said on Wednesday that the NightmareStresser booter service had been used since 2022 to launch hundreds of thousands of actual or attempted DDoS attacks against victims worldwide. The seizure banner displayed on the taken domains states that the enforcement action was supported by Operation PowerOFF. That effort is described as a coordinated push among international law enforcement agencies aimed at dismantling criminal DDoS-for-hire infrastructure globally.

The action follows earlier US enforcement against the same platform. In December 2022, the Department of Justice took down the nightmarestresser[.]com domain and arrested six suspects who allegedly owned multiple DDoS-for-hire services. Operation PowerOFF itself is an ongoing joint law enforcement action that began in December 2018 with the seizure of 15 websites tied to DDoS-as-a-service platforms.

Under Operation PowerOFF, authorities have previously taken down the DigitalStress DDoS-for-hire service in the United Kingdom and seized the Dstat.cc DDoS review platform. Two stresser service operators were arrested in Poland. In other joint actions connected to the operation, law enforcement seized 13 domains and 48 additional domains hosting booter platforms in two separate enforcement waves.

Polish authorities also detained four suspects last year linked to six DDoS-for-hire platforms behind thousands of attacks since 2022. Those attacks targeted schools, government services, businesses and gaming platforms worldwide, while the US seized nine domains in the same coordinated crackdown on DDoS services. The FBI's Cyber Division confirmed the NightmareStresser enforcement action.

More cybersecurity news from TechManNews.