FBI seizes NightmareStresser domains
Law Enforcement
Summary
Hide ▲
Show ▼
FBI seized nightmare-stresser[.]com and nightmarestresser[.]org, disrupting NightmareStresser, a long-running DDoS-for-hire service. The U.S. Department of Justice said the domain seizure was part of Operation PowerOFF and involved a coordinated law-enforcement action. Authorities said the service had been active since at least 2022 and was used to launch hundreds of thousands of DDoS attacks against victims worldwide. Prior reporting also tied the platform to 566,000+ registered users and 52 servers.
Related Happenings
Vo1d botnet campaign targeting unofficial Android-based TV boxes
Campaign
H score88
First: 18.06.2026 20:37
Last: 18.06.2026 20:37
Sources 1
About this happening:
NetNut used the Popa botnet and deceptive SDKs on off-brand Android-based smart TVs, streaming media boxes, and unofficial apps to turn home connections into residen...
Vo1d botnet campaign targeting unofficial Android-based TV boxes
CampaignAbout this happening: NetNut used the Popa botnet and deceptive SDKs on off-brand Android-based smart TVs, streaming media boxes, and unofficial apps to turn home connections into residen...
Latest development: 03.07.2026 12:35
Google disabled all Google accounts used by NetNut for malware command-and-control, updated Google Play Protect to warn Android users, and disabled apps containing the compromised SDKs. The FBI’s seizure banner appeared on netnut.com while netnut.io briefly remained accessible, and Google said the coordinated actions caused significant degradation to NetNut’s proxy network and business operations.
SocGholish malware downloader hijacking WordPress sites
Malware Activity
H score57
First: 18.06.2026 16:25
Last: 18.06.2026 16:25
Sources 1
About this happening:
SocGholish is a long-running JavaScript-based malware downloader also tracked as FakeUpdates that hijacks compromised WordPress sites to push fake browser update...
SocGholish malware downloader hijacking WordPress sites
Malware ActivityAbout this happening: SocGholish is a long-running JavaScript-based malware downloader also tracked as FakeUpdates that hijacks compromised WordPress sites to push fake browser update...
DOJ seizure of CFAKE.com and SOCFAKE.com deepfake domains
Law Enforcement
H score26
First: 16.06.2026 00:56
Last: 16.06.2026 00:56
Sources 1
About this happening:
The U.S. Department of Justice and Homeland Security Investigations seized CFAKE.com and SOCFAKE.com, disrupting a deepfake pornography operation and taking th...
DOJ seizure of CFAKE.com and SOCFAKE.com deepfake domains
Law EnforcementAbout this happening: The U.S. Department of Justice and Homeland Security Investigations seized CFAKE.com and SOCFAKE.com, disrupting a deepfake pornography operation and taking th...
FBI takedown of Outsider Enterprise phishing service
Law Enforcement
H score63
First: 14.06.2026 17:36
Last: 14.06.2026 17:36
Sources 1
About this happening:
FBI, Google, and Black Lotus Labs dismantled Outsider Enterprise, a phishing-as-a-service network that used SMS campaigns through AT&T, T-Mobile, a...
FBI takedown of Outsider Enterprise phishing service
Law EnforcementAbout this happening: FBI, Google, and Black Lotus Labs dismantled Outsider Enterprise, a phishing-as-a-service network that used SMS campaigns through AT&T, T-Mobile, a...
Latest development: 03.09.2026 17:00
The ChenLun-run Outsider Phishing Kit kept generating phishing campaigns after Operation Ghost Hook, with Group-IB identifying more than 700 new phishing pages within a month of the disruption and more than 100,000 phishing pages targeting 54 or more countries between December 2025 and May 2026.
Kimwolf operators build a cybercrime-as-a-service DDoS access market
Threat Actor Meta
H score24
First: 22.05.2026 11:50
Last: 22.05.2026 11:50
Sources 1
About this happening:
The Kimwolf operators ran a cybercrime-as-a-service market that sold access to infected devices, widening DDoS-for-hire abuse. The model turned compromised digital p...
Kimwolf operators build a cybercrime-as-a-service DDoS access market
Threat Actor MetaAbout this happening: The Kimwolf operators ran a cybercrime-as-a-service market that sold access to infected devices, widening DDoS-for-hire abuse. The model turned compromised digital p...
Timeline
-
17.09.2026 14:33 4 articles · 4d ago
FBI seizes NightmareStresser domains
Legal Policy Action UpdateThe FBI seized nightmare-stresser[.]com and nightmarestresser[.]org, taking down the domains used to reach NightmareStresser, a long-running DDoS-for-hire platform that let customers rent compromised routers and IoT devices for massive denial-of-service attacks.
Show sources
- US takes down NightmareStresser DDoS-for-hire platform — www.bleepingcomputer.com — 17.09.2026 14:33
- US takes down NightmareStresser DDoS-for-hire platform — www.bleepingcomputer.com — 17.09.2026 14:33
- U.S. Seizes NightmareStresser Domains Linked to Hundreds of Thousands of DDoS Attacks — thehackernews.com — 17.09.2026 08:13
- NightmareStresser DDoS Service Disrupted in International Operation — www.securityweek.com — 18.09.2026 13:12
-
17.09.2026 14:33 1 articles · 4d ago
FBI says NightmareStresser was used for hundreds of thousands of DDoS attacks
Campaign Scope UpdateThe FBI Cyber Division said NightmareStresser Booter service had been used since 2022 to launch hundreds of thousands of actual or attempted DDoS attacks targeting victims worldwide, and the seizure banner said the enforcement action was supported by Operation PowerOFF.
Show sources
- US takes down NightmareStresser DDoS-for-hire platform — www.bleepingcomputer.com — 17.09.2026 14:33