Skip to content
FBI Seizes NightmareStresser DDoS-for-Hire Domains in Alaska

FBI Seizes NightmareStresser DDoS-for-Hire Domains in Alaska

Technadu September 17, 2026

Domains seized: The FBI took down internet infrastructure tied to NightmareStresser, a long-running DDoS-for-hire "booter" service.

Scale of harm: The service launched hundreds of thousands of actual or attempted DDoS attacks worldwide since 2022.

Broader crackdown: Alaska prosecutors have now seized 100+ domains and charged 12 defendants over eight years of enforcement.

Domains linked to NightmareStresser, a "Booter" service the U.S. Attorney's Office for the District of Alaska describes as one of the world's longest-running DDoS-for-hire operations, were seised. The U.S. Department of Justice (DOJ) announced on September 15, 2026, a court-authorized seizure action shutting down websites that let paying customers launch attacks against targets in Alaska and around the globe.

What the Service Actually Did

Per the seizure warrant affidavit, NightmareStresser was used to launch hundreds of thousands of real or attempted Distributed Denial of Service attacks since 2022, the DOJ report said .

Booter and stresser platforms like this one have historically hit educational institutions, government agencies, gaming platforms, and ordinary users by the millions – degrading internet service or knocking targets offline entirely, the "booting" that gives these tools their name.

Officials note such services keep multiplying because they give low-skill users an easy entry point into cybercrime.

A Joint U.S.-Canada Operation

The FBI's Anchorage Field Office carried out the seizures alongside the Royal Canadian Mounted Police's Federal Policing Northwest Region. The action falls under Operation PowerOFF, an ongoing international effort to dismantle DDoS -for-hire infrastructure and hold both administrators and paying users accountable.

Part of an Eight-Year Enforcement Pattern

This takedown extends a longer campaign: over the past eight years, prosecutors and investigators in Anchorage and Los Angeles have charged twelve defendants and seized more than 100 domains connected to DDoS-for-hire services.

Authorities say the current investigation is targeting all known booter sites, aiming to shut down as many as possible while running a parallel public-education effort.

In May, Dutch authorities seized 800 servers linked to Russian cyberattacks and arrested two individuals, and the administrator of the KimWolf DDoS botnet was arrested following the infrastructure takedown.

An August Talos report warned that cybercriminals use AI to build botnets , steal crypto, and hijack live cameras.

Extracted Entities

Attack Types (1)

Campaigns (1)

Countries (1)

Industries (1)

Malware (1)