The FBI Just Killed NightmareStresser, a DDoS-for-Hire Service Behind Hundreds of Thousands of Hits
A court-authorized FBI seizure, announced around 16 September 2026, took NightmareStresser domains after a warrant affidavit said the booter launched hundreds of thousands of DDoS attacks since 2022. Anchorage and Los Angeles prosecutors have charged 12 defendants and seized more than 100 related domains over eight years.

Help Net Security (Sinisa Markovic, 17 September 2026) reported the FBI seized the domains behind NightmareStresser, a DDoS-for-hire booter officials call one of the longest-running operations of its kind. PC Mag (Michael Kan, 16 September 2026) reported the Justice Department announcement the same week.
This is a court-authorized domain seizure by the FBI and the U.S. Department of Justice, announced around 15 to 17 September 2026. It is part of Operation PowerOFF with the Royal Canadian Mounted Police. It is not a CVE, not a product exploit, and not a ransomware takedown.
The seizure warrant affidavit, as quoted by DoJ and Help Net Security, says NightmareStresser was used to launch hundreds of thousands of actual or attempted DDoS attacks against victims worldwide since 2022. DoJ said booter services facilitate attacks on educational institutions, government agencies, gaming platforms, and millions of people. The operation was meant to disrupt infrastructure used against victims in the District of Alaska and across the United States.
The FBI Anchorage Field Office led the seizure with RCMP Federal Policing Northwest Region. Domains replaced with FBI notices include nightmare-stresser.com, and reporting also names nightmarestresser.org. A related nightmarestresser.com domain was seized in 2022, and the site itself claimed more than eight years online.
Over the past eight years, prosecutors in Anchorage and Los Angeles have charged twelve defendants for running DDoS-for-hire services and seized more than 100 related domains. PC Mag, citing a 2023 Searchlight Cyber report, said the service had on the order of 566,000 registered users and priced attacks from about 25 euros to 19,999 euros.
The Record reported DoJ declined to say whether anyone was arrested in this September action. PC Mag noted the service could return under a new site. The attack counts come from the seizure warrant affidavit as reported by DoJ.
Related disruption tape includes the BragJack browser AI extension hijack, the Brevo ClickFix supply-chain hit, and the HBO Max Reddit ClickFix campaign.
SOC and network leads should treat NightmareStresser as disrupted, not gone, block the seized domains and lookalike stresser panels, and hunt logs for outbound hits to booter infrastructure since 2022.
Cyberpresso: daily cyber & AI brief
Free daily newsletter, read in 5 minutes.
Subscribe free