FBI, DOJ, and RCMP Seize NightmareStresser DDoS-for-Hire Domains in Latest Operation PowerOFF Action
FBI, DOJ, and RCMP Seize NightmareStresser DDoS-for-Hire (TL-2026-2549), also tracked as Operation PowerOFF (NightmareStresser action), is a medium-severity tracked intrusion set, first published 2026-09-17. It is attributed to NightmareStresser operators with low confidence, affects N/A NightmareStresser DDoS-for-hire ('booter'/'stresser') platform, maps to 11 MITRE ATT&CK techniques (T1071, T1110.001, T1498.001), and is covered by 9 detection rules and 16 indicators of compromise.
Key facts for TL-2026-2549
- Threat ID
- TL-2026-2549
- Also known as
- Operation PowerOFF (NightmareStresser action)
- Severity
- MEDIUM
- Status
- MITIGATED
- Category
- THREAT_INTEL
- First published
- 2026-09-17
- Last reviewed
- 2026-09-17
- Attribution
- NightmareStresser operators
- Attribution confidence
- LOW
- Motivation
- FINANCIAL
- Target sectors
- education, government administration, gaming, consumer
- Target regions
- North America, Global
- Detection rules
- 9
- Indicators of compromise
- 16
Malware and tooling in FBI, DOJ, and RCMP Seize NightmareStresser DDoS-for-Hire
Malware and tooling: Mythical Stress, NightmareStresser, Quantum, Vac Stresser
On September 15, 2026, the FBI's Anchorage field office, the U.S. Attorney's Office for the District of Alaska, and the Royal Canadian Mounted Police seized the nightmarestresser.com and nightmarestresser.org domains, dismantling one of the longest-running DDoS-for-hire ('booter'/'stresser') platforms. NightmareStresser operated since at least 2022, claimed over 566,000 registered users and an affiliate program, ran attacks from 52 dedicated servers against a botnet of compromised routers and IoT devices, and was linked to hundreds of thousands of DDoS attacks or attempted attacks against education, government, gaming, and individual victims worldwide.
How FBI, DOJ, and RCMP Seize NightmareStresser DDoS-for-Hire works
NightmareStresser was a subscription-based DDoS-for-hire ('booter'/'stresser') service that marketed itself as the 'longest-running, most powerful' platform of its kind. Operating since at least 2022, it allowed paying customers -- with no technical skill required -- to rent access to a botnet built from compromised home routers and IoT devices and direct it against a target of their choosing. Reporting on the seizure put the platform's attack capacity at up to 200 Gbps, delivered via both Layer 4 (TCP/UDP volumetric) and Layer 7 (application-layer) flooding, run from roughly 52 dedicated servers. NightmareStresser claimed over 566,000 registered users, offered an affiliate/referral program to reward recruiters, and sold attack packages at prices reportedly ranging from about EUR25 to nearly EUR20,000. Victims named by the Department of Justice include educational institutions, government agencies, gaming platforms, and millions of individuals in the United States and abroad. The platform's nightmarestresser.com domain had itself been a target of an earlier December 2022 Operation PowerOFF seizure action, indicating the operators re-established the service on the same or related domains before this second, more complete takedown. NightmareStresser marketed itself with unusual openness about supporting illegal use, describing its own customer base in terms of 'script kiddies' launching attacks for pranks or political agendas, and maintained a public Trustpilot storefront listing with a 3.9-out-of-5 rating and customer reviews ('I have been using the service for over a year. Everything is great.'). Its own marketing claimed operation 'under the laws of Russia' -- an unverified jurisdictional claim by the operators themselves, not a confirmed law-enforcement attribution, consistent with the LOW attribution confidence and unidentified-operator status of this threat record.
The September 15, 2026 seizure of nightmarestresser.com and nightmarestresser.org was carried out jointly by the FBI's Anchorage field office, the U.S. Attorney's Office for the District of Alaska (Assistant U.S. Attorneys Adam Alexander and Ainsley McNerney), and the Royal Canadian Mounted Police's Federal Policing Northwest Region, under the Computer Fraud and Abuse Act. It is the latest action in Operation PowerOFF, a multi-national law-enforcement initiative launched in December 2018 (FBI, Dutch National Police Corps) that has since expanded to include Europol, the UK National Crime Agency, Germany's Federal Criminal Police Office (BKA), Polish Cybercrime Police, and other partners across roughly 15-21 countries, with private-sector investigative support over the operation's history from providers including Cloudflare, PayPal, and DigitalOcean. Over its eight-year run, Operation PowerOFF has charged twelve defendants and seized more than 100 domains tied to booter/stresser services, including a December 2022 action that took down 48 domains (RoyalStresser.com, SecurityTeam.io, Astrostress.com, Booter.sx, Ipstressor.com, TrueSecurityServices.io, and the Quantum booter, the last linked to roughly 50,000 attacks), charged six U.S. defendants, and produced arrests spread across Florida (three), Texas, Hawaii, and New York; a December 2024 action that seized 27 domains across 15 countries, arrested three administrators (including Ricardo Cesar Colli, aka 'TotemanGames,' 22, of Brazil, who operated Securityhide.net) and identified roughly 300 customers; and an April 2026 action that seized eight domains, including Vac Stresser and Mythical Stress, across 20 countries, with Europol reporting four arrests and 25 search warrants and the operation cumulatively identifying roughly 75,000 booter-service users by that point. No individual operators of NightmareStresser itself had been publicly named or charged as of the September 2026 announcement.
MITRE ATT&CK techniques used in TL-2026-2549
Command and Control
T1071 Application Layer Protocol
Credential Access
Impact
T1498.001 Direct Network Flood; T1498.002 Reflection Amplification; T1499.003 Application Exhaustion Flood
Resource Development
T1583.001 Domains; T1583.004 Server; T1583.005 Botnet; T1583.006 Web Services; T1584.005 Botnet; T1584.008 Network Devices
Affected products and versions in FBI, DOJ, and RCMP Seize NightmareStresser DDoS-for-Hire
- N/A — NightmareStresser DDoS-for-hire ('booter'/'stresser') platform
Vulnerable versions: Active 2022 - September 15, 2026 (nightmarestresser.com, nightmarestresser.org)
Fixed in: Domains seized and service dismantled by FBI/DOJ/RCMP on 2026-09-15 - Various — Consumer routers and IoT devices recruited into DDoS botnets
Vulnerable versions: Devices with default/weak credentials or exposed remote-management interfaces
Fixed in: Not applicable; mitigated by credential hardening and firmware updates, not a vendor patch
Remediation for FBI, DOJ, and RCMP Seize NightmareStresser DDoS-for-Hire
Patches
- No CVE applies; apply vendor firmware updates on routers/IoT devices to close default-credential and remote-management weaknesses exploited to build DDoS botnets
Immediate actions
- Report ongoing DDoS activity to the FBI Internet Crime Complaint Center (IC3) and, for U.S. victims, the local FBI field office
- Engage upstream ISP or DDoS-scrubbing/CDN providers to filter volumetric Layer 4 and Layer 7 flood traffic during an active attack
- Rate-limit and geo/ASN-filter traffic from known booter attack infrastructure and reflection/amplification sources
Workarounds
- Maintain incident-response runbooks and pre-negotiated DDoS mitigation contracts so scrubbing can be activated quickly when a booter-driven flood is detected
Longer-term hardening
- Deploy always-on DDoS mitigation (cloud scrubbing, anycast, CDN) for internet-facing services in education, government, and gaming sectors historically targeted by booter services
- Harden consumer and SMB routers/IoT devices against botnet recruitment: change default credentials, disable unnecessary remote-management interfaces, and keep firmware current
- Participate in ISP-level BCP38/ingress filtering to reduce spoofed-source amplification traffic that booter platforms rely on
Timeline of FBI, DOJ, and RCMP Seize NightmareStresser DDoS-for-Hire
- FBI and Dutch National Police Corps launch Operation PowerOFF, seizing 15 DDoS-for-hire websites in the initiative's first coordinated action.
- NightmareStresser begins operating as a DDoS-for-hire booter/stresser service, marketed as the 'longest-running, most powerful' platform of its kind.
- DOJ/FBI Operation PowerOFF action seizes 48 booter domains -- including an earlier nightmarestresser.com seizure, RoyalStresser.com, SecurityTeam.io, Astrostress.com, Booter.sx, Ipstressor.com, TrueSecurityServices.io, and the Quantum booter (~50,000 attacks) -- and charges six U.S. defendants, with arrests spread across Florida (three), Texas, Hawaii, and New York.
- Europol-coordinated Operation PowerOFF action across 15 countries seizes 27 booter domains, arrests three administrators including Ricardo Cesar Colli ('TotemanGames') for operating Securityhide.net, and identifies roughly 300 customers.
- DOJ-led action across 20 countries seizes eight additional DDoS-for-hire domains, including Vac Stresser and Mythical Stress; Europol reports four arrests and 25 search warrants, with the operation's cumulative user identification reaching roughly 75,000 booter-service customers by this point.
- FBI's Anchorage field office, the U.S. Attorney's Office for the District of Alaska, and the Royal Canadian Mounted Police seize the nightmarestresser.com and nightmarestresser.org domains, dismantling NightmareStresser.
- DOJ and FBI Cyber Division publicly announce the NightmareStresser seizure; regional Alaska outlets report the action and quote the U.S. Attorney's Office.
- CyberScoop, Help Net Security, Cyber Daily, and other outlets report on the NightmareStresser takedown and its place within Operation PowerOFF's eight-year history.
Sources cited for FBI, DOJ, and RCMP Seize NightmareStresser DDoS-for-Hire
- FBI Seizes NightmareStresser DDoS-for-Hire Domains
- FBI Seizes DDoS-for-Hire Domains as Part of Continuing District of Alaska Crackdown on 'Booter' and 'Stresser' DDoS Services
- Prolific DDoS-for-hire service NightmareStresser seized by US authorities
- Alaska FBI targets DDoS-for-hire sites in international crackdown
- FBI takes down one of the longest-running DDoS-for-hire services
- US takes down NightmareStresser DDoS-for-hire platform
- Operation PowerOFF
- International crackdown disrupts DDoS-for-hire operations
- Feds Hit DDoS-for-Hire Services with 48 Domain Seizures
- NightmareStresser and Vac Stresser: DOJ takes down NightmareStresser DDoS platform
More in threat intel
- LLM-Driven Reverse Engineering of Palo Alto Cortex XDR Yields Working EDR Evasion (SpecterOps)
- France Dark Web Threat Landscape: Ransomware and Hacktivist Activity Surges 4x Over 24 Months
- Rehub: Russian-Language Ransomware-as-a-Service Marketplace Absorbing RAMP's Displaced Operators
- VSS Abuse: Attackers Weaponize Windows Volume Shadow Copy Service for Ransomware Prep and Credential Theft
- Blockchain-Based C2 Evolution: Nation-State Actors Adopt Smart-Contract C2 (EtherHiding, JADESNOW/INVISIBLEFERRET, SharkStealer)
Detection coverage for TL-2026-2549
As of 2026-09-17, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2549 across Splunk SPL, Microsoft KQL and Sigma, covering 16 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.