news.mlab.sh
Back to the feed
threat-intel

U.S. Seizes NightmareStresser Domains Linked to Hundreds of Thousands of DDoS Attacks

High
Summary

The U.S. Department of Justice seized over 100 internet domains linked to NightmareStresser, a DDoS-for-hire service, following a coordinated international law enforcement operation. The service, which operated since 2022, facilitated hundreds of thousands of attacks targeting various sectors, including educational institutions and government agencies. This action is part of Operation PowerOFF, a continuing effort to dismantle criminal DDoS-for-hire infrastructures globally.

The U.S. Department of Justice (DoJ) announced on Tuesday the seizure of over 100 internet domains associated with NightmareStresser, a distributed denial-of-service (DDoS)-for-hire service. These domains, including nightmare-stresser[.]com and nightmarestresser[.]org, were taken down as part of a joint international law enforcement operation involving the United States Attorney's Office for the District of Alaska, the Federal Bureau of Investigation (FBI) Anchorage Field Office, and the Royal Canadian Mounted Police (RCMP).

NightmareStresser has been operational since 2022 and has been used to launch hundreds of thousands of actual or attempted DDoS attacks against victims across the U.S. and globally. Targeted sectors included educational institutions, government agencies, and gaming platforms, impacting millions of users. The DoJ stated that these attacks can significantly degrade internet services and completely disrupt internet connections.

According to Searchlight Cyber, NightmareStresser boasted over 566,000 registered users and 52 servers, allowing attackers to target specific IP addresses or URLs and customize attack parameters, including port numbers and concurrent attack levels. The service offered advanced Layer 4 amplification methods and bypasses at Layer 4 over UDP/TCP and Layer 7, claiming the ability to defeat CAPTCHAs, geoblocks, and rate limits. A prominent feature was a “Stop All” button, enabling operators to instantly halt all active floods, regardless of layer.

NightmareStresser also utilized a referral system, rewarding users with credits for referring new customers, even if those customers didn't make immediate purchases. The DoJ has taken action against this service previously, seizing 48 domains in December 2022 and arresting four individuals in April 2023 as part of Operation PowerOFF, a broader initiative to dismantle criminal DDoS-for-hire infrastructures. These actions have resulted in the disruption of 53 domains and the apprehension of numerous cybercriminals.

“The multi-prong investigation announced today builds on the success of the prior cases by targeting all known booter sites, shutting down as many as possible, and undertaking a public education campaign,” the DoJ stated.

Read the full article at The Hacker News