NightmareStresser DDoS-for-Hire Service Shut Down in US-Led Action
US authorities seized the domains of a long-running DDoS-for-hire platform, disrupting attacks tied to hundreds of thousands of incidents.
Law enforcement has disrupted a major DDoS-for-hire service known as NightmareStresser. The US FBI and Department of Justice seized the domains used by the platform, which had been active since at least 2022. All three reports agree that this was one of the longest-running services of its kind, linked to a large volume of distributed denial-of-service attacks.
The sources vary slightly in framing. SecurityWeek describes an international operation, while BleepingComputer and The Hacker News attribute the action to US authorities, with the latter citing a court-authorized seizure. The exact number of attacks attributed to the service is reported by The Hacker News as hundreds of thousands, though the precise count is not consistent across all reports.
The seizure removes a significant tool from the DDoS-for-hire market, though such services often reappear under new names. The coordinated action highlights continued enforcement against cybercrime infrastructure.
Sources · 3
More in Security & Privacy
WordPress Click2Shell CSRF Flaw Could Let Attackers Run PHP Code
A newly disclosed cross-site request forgery vulnerability in WordPress Core, with a public proof-of-concept, can let attackers execute PHP on the server.
Film Torrents Carry New Malware, Victims Found in Kenya and Uganda
Cybercriminals are using popular movie torrents to distribute fresh malware, with confirmed infections in East Africa.
CrowdSec Breach: TanStack npm Attack Exposed 170 Private Repos
CrowdSec says an attacker used a former employee's still-active GitHub access to copy 170 private repositories, tracing the intrusion to the TanStack npm attack.
CISA Adds Three Exploited Linux Kernel Flaws to KEV Catalog
The agency's move signals active attacks and pressures federal agencies to patch quickly.