Security3 publishers2 min readPublished
FBI seizes NightmareStresser again, three years after the brand's first takedown
The Justice Department seized this service's original domain in December 2022 and arrested six people. The FBI has now taken two more of its domains, and the warrant affidavit counts hundreds of thousands of attacks since 2022.
The Watch · Security desk

What happened
- The FBI seized nightmare-stresser[.]com and nightmarestresser[.]org on Tuesday, and the Justice Department announced the court-authorized action out of the District of Alaska.
- The Justice Department had already taken the nightmarestresser[.]com domain in December 2022, arresting six people it said owned multiple DDoS-for-hire services.
- Searchlight Cyber counted more than 566,000 registered users, 52 dedicated servers and attacks of up to 200 Gbps behind the platform in 2023.
- The FBI's Anchorage Field Office ran the technical work with the Royal Canadian Mounted Police's Federal Policing Northwest Region, under Operation PowerOFF.
Compiled by The WatchSomething wrong?How this is made
Why it matters
- precedent A brand that came back on a hyphenated domain after its first seizure sets the expectation for this one, so the useful planning assumption is a replacement storefront.
- constraint Seizing domains removes a sales channel and leaves the rented capacity behind it intact. No defender gets to revise a mitigation budget downward on the strength of this action.
- exposure The victim set the department describes is schools, government agencies and gaming platforms, and the collateral reaches other users sharing the same network infrastructure.
- cost Enforcement here is expensive and slow while entry is cheap and fast, so the cost of each takedown lands on prosecutors.
The domain seized in December 2022 was nightmarestresser[.]com. The two taken this week are nightmare-stresser[.]com and nightmarestresser[.]org. The difference between the first takedown and the second is a hyphen and a top-level domain, and the affidavit's attack count begins in the same year the first domain came down.
What a booter sells is access to somebody else's hardware. Customers rent botnets of compromised routers and IoT devices, and the traffic comes from those devices. A warrant against two domains takes the shop window and the payment funnel. The compromised devices sit outside it.
Operation PowerOFF has run since December 2018, when it opened with 15 sites. Counting the waves these two reports enumerate: 15 in 2018, 27 in December 2024, 53 across 21 countries in April, and separate actions of 13, 48 and nine domains. That is at least 165 booter domains seized under one operation.
Prosecutors in Anchorage and Los Angeles have charged twelve defendants and seized more than 100 domains in eight years, about 1.5 defendants a year. The Justice Department said the current investigation "builds on the success of the prior cases by targeting all known booter sites, shutting down as many as possible, and undertaking a public education campaign."
The customer side of that campaign has some reach. April's coordinated action sent warning letters to more than 75,000 identified users of the platforms it took down, roughly 13 percent of the registered accounts Searchlight Cyber counted on NightmareStresser alone in 2023. Renting an attack cost a few dollars.
The Justice Department did not name a defendant in this action. "Since 2022, the NightmareStresser Booter service was used to launch hundreds of thousands of actual or attempted DDoS attacks targeting victims worldwide," the FBI Cyber Division said.
What to watch
- Whether an indictment naming NightmareStresser's operators follows, or the case stays a domain seizure.
- Whether the attack servers themselves are seized in a later wave, since domains are cheaper to replace than capacity.
- Whether attack volumes against Alaskan targets drop in the weeks after the seizure or hold flat.