Search TorWire

Find cybersecurity guides and research articles

Home > News > Cybersecurity > FBI and Canadian Police Seize Domains of Long-Running NightmareStresser DDoS Service

FBI and Canadian Police Seize Domains of Long-Running NightmareStresser DDoS Service

By: Morgan Cipher — Senior Privacy Journalist

Last updated: September 18, 2026

Human Written
FBI and Canadian Police Seize Domains of Long-Running NightmareStresser DDoS Service
  • The FBI and Royal Canadian Mounted Police seized domains for NightmareStresser, one of the world’s longest-running DDoS-for-hire services.

  • The service facilitated hundreds of thousands of attacks against government agencies, schools, gaming platforms, and personal users for four years.

  • This international action builds on years of enforcement that saw twelve operators charged and over 100 booter domains seized.

Federal law enforcement authorities in Alaska have seized internet domains linked to a major cybercrime platform. The service in question goes by the name of NightmareStresser, which has been in the business of performing DDoS attacks for a fee. 

Different web domains owned by NightmareStresser were seized by law enforcement via court warrants, as part of their investigation. Officials confirmed that paying customers used the infrastructure to attack victims worldwide.

Global Disruption of Booter and Stresser Attack Platforms

Booter and stresser platforms allow paying customers to launch powerful digital disruption attacks with ease. These commercial platforms flood targeted computer networks with overwhelming volumes of fake internet traffic. Consequently, targeted web servers freeze up and disconnect completely from global online networks.

The affidavit file shows that NightmareStresser had been responsible for numerous attacks, running into hundreds of thousands, for the past four years. The criminal group attacked various educational institutions, government agencies, online gaming sites, and public infrastructure systems several times. Furthermore, these malicious floods degraded baseline internet connectivity for millions of everyday users.

Government websites can also become targets during major DDoS campaigns. In a separate case, the Dark Storm Team claimed DDoS attacks on German government websites, highlighting how threat groups can use disruption attacks against public-sector infrastructure.

Technically, booter platforms lower entry barriers by allowing unskilled individuals to rent complex botnets. Anyone with basic digital payment access can order precise denial of service floods. Therefore, law enforcement agencies prioritize taking down these central distribution portals.

Cross-Border Law Enforcement Cooperation Under Operation PowerOFF

The Anchorage Field Office of the FBI executed the seizure warrants in cooperation with international police partners. More specifically, the FBI worked with the Royal Canadian Mounted Police Northwestern Region. The operation is part of a global initiative known as Operation PowerOFF.

Further, Operation PowerOFF connects law enforcement from North America and Europe to disband disruptive networks. The agencies within the operation share intelligence and criminal information, seize host computers, and prosecute the administrators of the criminal platforms. In the past eight years, the law authorities have charged twelve web operators in Anchorage and Los Angeles.

Meanwhile, federal authorities have seized over 100 domain names associated with booters during recent crackdown phases. Officers also run targeted public education campaigns to warn prospective buyers against using illegal platforms. These combined efforts aim to eliminate stressed platforms and hold individual users legally accountable.

The Processes Behind Distributed Denial of Service Floods

Denial of Service attacks employ certain network protocols to consume bandwidth, processing capabilities, and storage. Different stresser platforms are using User Datagram Protocol floods and Domain Name System amplification methods. As a result, victim firewalls struggle to differentiate between legitimate requests and malicious traffic streams.

Also, Booter operators rely on compromised IoT devices to create large distributed botnet networks. All these infected smart devices generate and send continuous data packets simultaneously to the target IP addresses. As a result, the target websites collapse almost instantly under the weight of huge incoming data.

Apart from consumer equipment, attackers can make use of badly configured public servers to multiply the amount of attack traffic by 10 times. The criminals direct small requests through open reflectors to create a massive response stream against their victims. Thus, a small paid fee for rental will provide access to huge network disruption capabilities on the dark web markets.

Preventive Processes and Defense for Infrastructure 

Organizations must implement several technical safeguards to mitigate incoming volumetric traffic floods effectively. IT Managers must deploy firewall defenses, as well as optimized usage of rate-limiting rules within their networks. Further, using automated content delivery networks will mitigate sudden bandwidth spikes in usage without compromising basic apps.

Moreover, network administrators should implement real-time feedback mechanisms to quickly alert them to traffic spikes. Finally, blocking suspicious traffic protocols via internet service providers can help protect the local network infrastructure. Proactive defense ensures that service is functioning even if hackers activate their automated attacks.

In the same way, enterprise networks should keep redundant cloud routing channels in case they need to redirect harmful traffic when they are facing attacks. Scrubbing centers monitor incoming packets in real-time to filter out fake bot traffic. Keeping updated emergency response protocols is vital for business continuity if there are prolonged network disruptions.

According to regulatory law, the act of utilizing or acquiring access to booter sites is a serious violation. Those found guilty of operating as the administrators or users will be subject to substantial monetary penalties as well as lengthy imprisonment sentences. Authorities employ surveillance mechanisms to capture the IP addresses, payment history, and identity of users whenever they take down these platforms.

Beside technical seizures, the authorities redirect confiscated web domains to exhibit official notifications. These messages warn visitors that cybercriminals are not able to hide their illegal activities from investigators because they create a permanent digital footprint. Thus, police can utilize confiscated customer information to send formal notices to registered users directly.

The prosecution of this case is currently under the direction of Assistant US Attorneys Adam Alexander and Ainsley McNerney. The federal authorities intend to continue putting a lot of pressure on the new booter substitutes all over the world. Public reporting and international cooperation remain essential to protecting critical digital infrastructure.

Share this article

You might also like

Hacker Claims Mistral AI Source Code is for Sale on Cybercrime Forum

Threat Actor Claims Full Source Code of French AI Firm Mistral is for Sale

A hacker using the alias mrwho claims to have the full source code of Mistral AI and is advertising it…

September 18, 2026
Iranian Hackers Use Fake Apps and Medical Scans to Spread CHOSEN BRICK Spyware

Iranian Hackers Use Fake Apps and Medical Scans to Spread CHOSEN BRICK Spyware

Iranian hackers hide a spy tool called CHOSEN BRICK inside fake apps and fake medical scans. The malware can watch…

September 17, 2026
US Charges Five Alleged Black Axe Leaders After Extradition from South Africa

US Charges Five Alleged Black Axe Leaders After Extradition from South Africa

Five men who are supposedly Black Axe leaders are now awaiting trials in the U.S. after an extended extradition battle.…

September 17, 2026

About the Author

Morgan Cipher

Morgan Cipher

Senior Privacy Journalist

Morgan combines a journalist’s curiosity with a security specialist’s precision. His reporting on data breaches, privacy laws, and encryption tech has been featured in several tech publications. At TorWire, he focuses on real-world threats and how to counter them, always with an eye on what’s next in digital privacy.

Comments (0)

No comments.