FBI Seized Domains of NightmareStresser DDoS Platform
The international takedown aims to disrupt criminal services capable of launching 200 Gbps cyberattacks.
Updated on Sept. 27, 2026 in Cybersecurity

Live Poll
Do you feel digital services you use are becoming less secure from cyber attacks?
The FBI has seized the domains of NightmareStresser, a platform that enabled users to purchase distributed denial-of-service (DDoS) attacks. This action follows previous domain seizures and is part of the ongoing multinational Operation PowerOFF.
Why it matters
Law enforcement targeted the platform to drive up the operational costs of cyber-attack services that exploit compromised IoT devices to overwhelm targets. These efforts reflect a sustained strategy to dismantle the infrastructure supporting criminal DDoS-for-hire markets.
The platform maintained a network of 52 dedicated servers to orchestrate traffic spikes reaching 200 Gbps. These services specifically utilized botnets composed of compromised routers and IoT devices.
The players
FBI
The domestic intelligence and security service of the United States which leads federal law enforcement investigations into cybercrime.
The details
NightmareStresser operated by renting out access to botnets, which are networks of internet-connected devices infected with malware that can be commanded remotely. By aggregating the bandwidth of compromised routers and IoT devices—objects like security cameras or smart appliances—the platform could generate high-volume traffic to overwhelm target servers, schools, or gaming platforms.
Timeline
2018: Operation PowerOFF began.
2022: NightmareStresser began operations.
December 2022: FBI previously seized the NightmareStresser domain.
September 22, 2026: FBI seized NightmareStresser domains.
The Tech Race
This seizure represents an ongoing effort by international law enforcement to systematically dismantle the infrastructure supporting DDoS-for-hire services. It builds upon the tactical framework established by Operation PowerOFF to degrade the capability of criminal groups.
Organizations and gaming platforms targeted by this service may see a temporary reduction in high-volume traffic disruptions. While the infrastructure is currently disabled, the marketplace for DDoS-for-hire remains volatile as operators attempt to migrate between domains.
The takeaway
The seizure of NightmareStresser illustrates the limits of using domain-level takedowns to curb decentralized botnet operations. Readers should monitor future coordination between the FBI and international partners to see if these operations evolve beyond repeated domain seizures.
Further reading
For broader context on these infrastructure disruptions, visit our coverage of Cybersecurity.
Source note: This article includes information reported by Computer Crime Research Center.
Live Poll
Do you feel digital services you use are becoming less secure from cyber attacks?






