U.S. Seizes NightmareStresser Domains Linked to Hundreds of Thousands of DDoS Attacks
- ID
- 25599
- Status
- summarized
- Published
- 17 Sep 2026, 1:13 PM
- Fetched
- 17 Sep 2026, 11:47 PM
- Provider
- The Hacker News
- Category
- security
- Original URL
- https://thehackernews.com/2026/09/us-seizes-nightmarestresser-domains.html
- Source URL
- https://feeds.feedburner.com/TheHackersNews
Summary
- Score
- 3.5
- Created
- 18 Sep 2026, 12:54 AM
- Tags
- Audience
- saas_foundersdevelopers
What happened
The U.S. DoJ and FBI, with Canadian RCMP support, seized domains for NightmareStresser, a DDoS-for-hire service active since 2022 with over 566,000 registered users and 52 servers. The service was used to launch hundreds of thousands of DDoS attacks against educational institutions, government agencies, gaming platforms, and individuals, and was protected by BlazingFast infrastructure.
Why it matters
One booter takedown doesn't eliminate DDoS risk; SaaS founders hosting in Malaysia or SEA should verify their cloud or CDN provider includes DDoS mitigation (e.g., Cloudflare, AWS Shield) since booter services with hundreds of thousands of users remain cheap and accessible to attackers targeting small platforms.
Discussion angle
Whether your current hosting setup would survive a DDoS attack from a $10/month booter subscription, and what mitigation layer you actually have versus what you assume you have.