NightmareStresser was a long-running DDoS-for-hire, or booter/stresser, service that enabled paying customers to direct distributed denial-of-service attacks against selected websites, servers, and networks. Active since at least 2022, it was reportedly used for hundreds of thousands of attacks or attempted attacks worldwide. Targets included educational institutions, government agencies, gaming platforms, and individual users. The service openly marketed illegal attack capabilities and operated an affiliate program. U.S. and Canadian law enforcement seized its online infrastructure in September 2026 as part of Operation PowerOFF, an international campaign against DDoS-for-hire services. The operators were not publicly identified. The operation reflects Network Denial of Service behavior and use of acquired domain infrastructure.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
2 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
3 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Service cybercriminel DDoS-for-hire/booter-stresser utilisé depuis 2022 pour lancer ou tenter des centaines de milliers d'attaques par déni de service distribué contre des victimes internationales. Ses domaines ont été saisis dans le cadre d'Operation PowerOFF.
A DDoS-for-hire (booter/stresser) operation whose service was used by customers globally to conduct large-scale DDoS attacks. It openly marketed illegal use cases, operated an affiliate program, and claimed tens of thousands of users. Its primary domain and associated sites were seized under Operation PowerOFF.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.