Advertisement

Authorities seize popular, long-running DDoS-for-hire service domains

Cybercriminals used NightmareStresser to launch hundreds of thousands of DDoS attacks since at least 2022. Threat actors behind the operation claimed links to Russia.
Listen to this article
0:00
Learn more. This feature uses an automated voice, which may result in occasional errors in pronunciation, tone, or sentiment.
(Getty Images)

Authorities seized the primary domain and other websites linked to NightmareStresser, one of the longest-running and most popular distributed denial-of-service operations used by cybercriminals globally, the Justice Department said Tuesday. 

Cybercriminals of various motivations used the DDoS-for-hire service to launch hundreds of thousands of DDoS attacks or attempted attacks since at least 2022, officials said. 

The takedown, part of an ongoing globally coordinated effort dubbed “Operation PowerOFF,” marks law enforcement’s continued targeting of IP stressers or DDoS booters that inundate websites, servers and networks with junk traffic, rendering legitimate sites inaccessible. The seizures were executed by the FBI Anchorage field office and the Royal Canadian Mounted Police.

Officials didn’t name the operators of NightmareStresser or identify its country of origin, but the service claimed it operated under the laws of Russia, Zach Edwards, staff threat researcher at Infoblox told CyberScoop.

Advertisement

The court-ordered seizure of NightmareStresser’s primary domain, which operated openly on the public web and now displays a seizure notice, is a positive development in the fight against DDoS-for-hire threat actors, Edwards said. Yet, he added, “it’s somewhat shocking that it’s taken law enforcement this long to take action.”

Authorities said they’ve seized more than 100 domains associated with DDoS-for-hire services since 2018. 

Despite those efforts, DDoS-for-hire tools remain prolific and easily accessible, often including tutorials that allow non-tech savvy people to initiate attacks on various organizations. 

“The vast majority of people who actually use DDoS services like NightmareStresser are script kiddies, oftentimes for pranks or for some sort of obscure political agenda. These services have been heavily used against gaming servers and streamers,” Edwards said.

Officials said NightmareStresser’s customers targeted various victims in the United States and abroad, including educational institutions, government agencies, gaming platforms and millions of people.

Advertisement

The DDoS-for-hire service’s operators claimed tens of thousands of users, Edwards said. “NightmareStresser is unique because of how long they’ve operated, their aggressive marketing which was pretty open about supporting illegal use cases, and their affiliate program which was used to reward partners,” he added. 

Authorities are now likely attempting to identify the operators of NightmareStresser, its business partners and people who used the service, according to Edwards. 

“Unfortunately for law enforcement, threat actors behind NightmareStresser claimed they were operating under the laws of the Russian Federation, which is a strong sign that it may be challenging to bring these folks to justice, even if they are known and doxxed,” he said. 

The impact of the seizures may also be temporary, at best. “The reality is that these booter services are like playing a game of Whac-A-Mole,” Edwards said. “There’s always another suspicious service operating similar DDoS products, and these underground networks quickly shift to new providers when one is taken down.”

Latest Podcasts