FBI, DOJ, and RCMP Seize NightmareStresser DDoS-for-Hire Domains in Latest Operation PowerOFF Action

FBI, DOJ, and RCMP Seize NightmareStresser DDoS-for-Hire (TL-2026-2549), also tracked as Operation PowerOFF (NightmareStresser action), is a medium-severity tracked intrusion set, first published 2026-09-17. It is attributed to NightmareStresser operators with low confidence, affects N/A NightmareStresser DDoS-for-hire ('booter'/'stresser') platform, maps to 11 MITRE ATT&CK techniques (T1071, T1110.001, T1498.001), and is covered by 9 detection rules and 16 indicators of compromise.

Key facts for TL-2026-2549

Threat ID
TL-2026-2549
Also known as
Operation PowerOFF (NightmareStresser action)
Severity
MEDIUM
Status
MITIGATED
Category
THREAT_INTEL
First published
2026-09-17
Last reviewed
2026-09-17
Attribution
NightmareStresser operators
Attribution confidence
LOW
Motivation
FINANCIAL
Target sectors
education, government administration, gaming, consumer
Target regions
North America, Global
Detection rules
9
Indicators of compromise
16

Malware and tooling in FBI, DOJ, and RCMP Seize NightmareStresser DDoS-for-Hire

Malware and tooling: Mythical Stress, NightmareStresser, Quantum, Vac Stresser

On September 15, 2026, the FBI's Anchorage field office, the U.S. Attorney's Office for the District of Alaska, and the Royal Canadian Mounted Police seized the nightmarestresser.com and nightmarestresser.org domains, dismantling one of the longest-running DDoS-for-hire ('booter'/'stresser') platforms. NightmareStresser operated since at least 2022, claimed over 566,000 registered users and an affiliate program, ran attacks from 52 dedicated servers against a botnet of compromised routers and IoT devices, and was linked to hundreds of thousands of DDoS attacks or attempted attacks against education, government, gaming, and individual victims worldwide.

How FBI, DOJ, and RCMP Seize NightmareStresser DDoS-for-Hire works

NightmareStresser was a subscription-based DDoS-for-hire ('booter'/'stresser') service that marketed itself as the 'longest-running, most powerful' platform of its kind. Operating since at least 2022, it allowed paying customers -- with no technical skill required -- to rent access to a botnet built from compromised home routers and IoT devices and direct it against a target of their choosing. Reporting on the seizure put the platform's attack capacity at up to 200 Gbps, delivered via both Layer 4 (TCP/UDP volumetric) and Layer 7 (application-layer) flooding, run from roughly 52 dedicated servers. NightmareStresser claimed over 566,000 registered users, offered an affiliate/referral program to reward recruiters, and sold attack packages at prices reportedly ranging from about EUR25 to nearly EUR20,000. Victims named by the Department of Justice include educational institutions, government agencies, gaming platforms, and millions of individuals in the United States and abroad. The platform's nightmarestresser.com domain had itself been a target of an earlier December 2022 Operation PowerOFF seizure action, indicating the operators re-established the service on the same or related domains before this second, more complete takedown. NightmareStresser marketed itself with unusual openness about supporting illegal use, describing its own customer base in terms of 'script kiddies' launching attacks for pranks or political agendas, and maintained a public Trustpilot storefront listing with a 3.9-out-of-5 rating and customer reviews ('I have been using the service for over a year. Everything is great.'). Its own marketing claimed operation 'under the laws of Russia' -- an unverified jurisdictional claim by the operators themselves, not a confirmed law-enforcement attribution, consistent with the LOW attribution confidence and unidentified-operator status of this threat record.

The September 15, 2026 seizure of nightmarestresser.com and nightmarestresser.org was carried out jointly by the FBI's Anchorage field office, the U.S. Attorney's Office for the District of Alaska (Assistant U.S. Attorneys Adam Alexander and Ainsley McNerney), and the Royal Canadian Mounted Police's Federal Policing Northwest Region, under the Computer Fraud and Abuse Act. It is the latest action in Operation PowerOFF, a multi-national law-enforcement initiative launched in December 2018 (FBI, Dutch National Police Corps) that has since expanded to include Europol, the UK National Crime Agency, Germany's Federal Criminal Police Office (BKA), Polish Cybercrime Police, and other partners across roughly 15-21 countries, with private-sector investigative support over the operation's history from providers including Cloudflare, PayPal, and DigitalOcean. Over its eight-year run, Operation PowerOFF has charged twelve defendants and seized more than 100 domains tied to booter/stresser services, including a December 2022 action that took down 48 domains (RoyalStresser.com, SecurityTeam.io, Astrostress.com, Booter.sx, Ipstressor.com, TrueSecurityServices.io, and the Quantum booter, the last linked to roughly 50,000 attacks), charged six U.S. defendants, and produced arrests spread across Florida (three), Texas, Hawaii, and New York; a December 2024 action that seized 27 domains across 15 countries, arrested three administrators (including Ricardo Cesar Colli, aka 'TotemanGames,' 22, of Brazil, who operated Securityhide.net) and identified roughly 300 customers; and an April 2026 action that seized eight domains, including Vac Stresser and Mythical Stress, across 20 countries, with Europol reporting four arrests and 25 search warrants and the operation cumulatively identifying roughly 75,000 booter-service users by that point. No individual operators of NightmareStresser itself had been publicly named or charged as of the September 2026 announcement.

MITRE ATT&CK techniques used in TL-2026-2549

Command and Control

T1071 Application Layer Protocol

Credential Access

T1110.001 Password Guessing

Impact

T1498.001 Direct Network Flood; T1498.002 Reflection Amplification; T1499.003 Application Exhaustion Flood

Resource Development

T1583.001 Domains; T1583.004 Server; T1583.005 Botnet; T1583.006 Web Services; T1584.005 Botnet; T1584.008 Network Devices

Affected products and versions in FBI, DOJ, and RCMP Seize NightmareStresser DDoS-for-Hire

  • N/A — NightmareStresser DDoS-for-hire ('booter'/'stresser') platform
    Vulnerable versions: Active 2022 - September 15, 2026 (nightmarestresser.com, nightmarestresser.org)
    Fixed in: Domains seized and service dismantled by FBI/DOJ/RCMP on 2026-09-15
  • Various — Consumer routers and IoT devices recruited into DDoS botnets
    Vulnerable versions: Devices with default/weak credentials or exposed remote-management interfaces
    Fixed in: Not applicable; mitigated by credential hardening and firmware updates, not a vendor patch

Remediation for FBI, DOJ, and RCMP Seize NightmareStresser DDoS-for-Hire

Patches

  • No CVE applies; apply vendor firmware updates on routers/IoT devices to close default-credential and remote-management weaknesses exploited to build DDoS botnets

Immediate actions

  • Report ongoing DDoS activity to the FBI Internet Crime Complaint Center (IC3) and, for U.S. victims, the local FBI field office
  • Engage upstream ISP or DDoS-scrubbing/CDN providers to filter volumetric Layer 4 and Layer 7 flood traffic during an active attack
  • Rate-limit and geo/ASN-filter traffic from known booter attack infrastructure and reflection/amplification sources

Workarounds

  • Maintain incident-response runbooks and pre-negotiated DDoS mitigation contracts so scrubbing can be activated quickly when a booter-driven flood is detected

Longer-term hardening

  • Deploy always-on DDoS mitigation (cloud scrubbing, anycast, CDN) for internet-facing services in education, government, and gaming sectors historically targeted by booter services
  • Harden consumer and SMB routers/IoT devices against botnet recruitment: change default credentials, disable unnecessary remote-management interfaces, and keep firmware current
  • Participate in ISP-level BCP38/ingress filtering to reduce spoofed-source amplification traffic that booter platforms rely on

Timeline of FBI, DOJ, and RCMP Seize NightmareStresser DDoS-for-Hire

  • FBI and Dutch National Police Corps launch Operation PowerOFF, seizing 15 DDoS-for-hire websites in the initiative's first coordinated action.
  • NightmareStresser begins operating as a DDoS-for-hire booter/stresser service, marketed as the 'longest-running, most powerful' platform of its kind.
  • DOJ/FBI Operation PowerOFF action seizes 48 booter domains -- including an earlier nightmarestresser.com seizure, RoyalStresser.com, SecurityTeam.io, Astrostress.com, Booter.sx, Ipstressor.com, TrueSecurityServices.io, and the Quantum booter (~50,000 attacks) -- and charges six U.S. defendants, with arrests spread across Florida (three), Texas, Hawaii, and New York.
  • Europol-coordinated Operation PowerOFF action across 15 countries seizes 27 booter domains, arrests three administrators including Ricardo Cesar Colli ('TotemanGames') for operating Securityhide.net, and identifies roughly 300 customers.
  • DOJ-led action across 20 countries seizes eight additional DDoS-for-hire domains, including Vac Stresser and Mythical Stress; Europol reports four arrests and 25 search warrants, with the operation's cumulative user identification reaching roughly 75,000 booter-service customers by this point.
  • FBI's Anchorage field office, the U.S. Attorney's Office for the District of Alaska, and the Royal Canadian Mounted Police seize the nightmarestresser.com and nightmarestresser.org domains, dismantling NightmareStresser.
  • DOJ and FBI Cyber Division publicly announce the NightmareStresser seizure; regional Alaska outlets report the action and quote the U.S. Attorney's Office.
  • CyberScoop, Help Net Security, Cyber Daily, and other outlets report on the NightmareStresser takedown and its place within Operation PowerOFF's eight-year history.

Sources cited for FBI, DOJ, and RCMP Seize NightmareStresser DDoS-for-Hire

More in threat intel

Detection coverage for TL-2026-2549

As of 2026-09-17, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2549 across Splunk SPL, Microsoft KQL and Sigma, covering 16 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats