FBI Seizes NightmareStresser Domains Used for DDoS Attacks-for-Hire
U.S. authorities seized domains linked to the NightmareStresser service. According to a court filing, it was used in hundreds of thousands of DDoS attacks or attempted attacks since 2022.

The U.S. Department of Justice announced the court-authorized seizure of NightmareStresser domains, a service offering DDoS attacks for hire. The action is part of the international Operation PowerOFF, which targets so-called booter or stresser services.
The operation was carried out by the FBI’s Anchorage field office in coordination with the Royal Canadian Mounted Police (RCMP). Authorities said the goal was to disrupt infrastructure used to facilitate attacks.
Seizure of NightmareStresser Domains as Part of Operation PowerOFF
According to the affidavit attached to the seizure warrant, the NightmareStresser service has been used since 2022 in hundreds of thousands of completed or attempted distributed denial-of-service attacks, known as DDoS attacks. In such an attack, a large volume of requests overwhelms a target system or network, which may limit or completely interrupt the availability of an online service.
Booter/stresser services provide customers with the technical means to carry out DDoS attacks for hire. This lowers the barrier to entry for attackers, who do not need to build the necessary attack infrastructure themselves. In this context, the Department of Justice lists targets including schools, government offices and gaming platforms.
Operation PowerOFF is a longer-term international effort targeting operators and users of similar services. The current announcement specifically concerns the court-ordered seizure of domains linked to NightmareStresser.
What the Action Confirms and What It Does Not Yet
The seizure may immediately restrict users’ access to the service and reduce the availability of its attack capacity. However, the announcement itself does not confirm that authorities have removed NightmareStresser’s entire technical infrastructure or that its operators cannot move the service to other domains or infrastructure.
The Department of Justice also did not announce any new arrests or charges directly connected to this seizure. The identities of the operators, the exact number of victims and the extent of the damage caused were not disclosed.
What to Watch Next
- whether U.S. or Canadian authorities announce charges or arrests, or release additional court documents,
- whether replacement domains appear or the service moves to other infrastructure,
- further actions under Operation PowerOFF.
Sources
- U.S. Department of Justice, U.S. Attorney’s Office for the District of Alaska – Confirms the court-ordered seizure of the domains, the involvement of the FBI Anchorage field office and RCMP, the connection to Operation PowerOFF, and the filing’s claim of hundreds of thousands of attacks since 2022.
- BleepingComputer – Independently reports that the service domains display a seizure notice and provides context on previous actions against booter services.
Verified and updated: 09/17/2026 15:22



