To ensure the best browsing experience, please enable JavaScript in your web browser. Without it, many website features are inaccessible.


Total Tests:
485,773,462
737,046
130,956

FBI seized NightmareStresser DDoS-for-hire infrastructure

September 17, 2026

Read also: malware developer sentences to 12 years by Swiss court; Black Axe leaders extradited to US; and more.

Views: 808 Read Time: 4 min.

FBI seized NightmareStresser DDoS-for-hire infrastructure

FBI dismantled NightmareStresser DDoS-for-hire infrastructure

The U.S. Federal Bureau of Investigation (FBI) has seized internet domains associated with NightmareStresser, a long-running distributed denial-of-service (DDoS) for-hire platform used to conduct cyberattacks against organizations worldwide.

According to the official announcement from the U.S. Department of Justice (DOJ), the domains were seized under court authorization as part of an operation conducted by the FBI Anchorage Field Office in coordination with the Royal Canadian Mounted Police. The action forms part of Operation PowerOFF, an international law enforcement initiative targeting criminal DDoS-for-hire infrastructure and its operators.

According to the seizure warrant affidavit cited by the DOJ, NightmareStresser had been used to launch hundreds of thousands of actual or attempted DDoS attacks against targets worldwide since 2022. Such services, commonly referred to as "booters" or "stressers," allow customers to pay for attacks that overwhelm targeted systems with traffic, potentially making websites and other internet services unavailable.

The DOJ said DDoS-for-hire services have been used to target educational institutions, government agencies, gaming platforms and other victims in the United States and abroad. The latest action continues a broader crackdown in which U.S. authorities have charged 12 defendants and seized more than 100 domains associated with DDoS-for-hire services over the past eight years.

Swiss court sentenced malware developer to 12 years imprisonment

A Swiss court has sentenced a 52-year-old Ukrainian national to 12 years and nine months imprisonment for his role in ransomware attacks against companies in Switzerland and other countries. The Zurich District Court also ordered the defendant to be expelled from Switzerland for ten years.

According to Swiss public broadcaster SRF and Keystone-SDA, the court concluded that the defendant developed key components of the LockerGoga, MegaCortex and Nefilim ransomware families and supplied the malware to other members of the criminal operation. The attackers targeted organizations including Swiss train manufacturer Stadler Rail, building technology company Meier Tobler and financial software provider Crealogix.

During the attack against Stadler Rail, approximately 500 GB of confidential information was stolen and the attackers threatened to publish the data unless a ransom was paid. Stadler Rail refused to pay, although other victims reportedly made payments. Prosecutors estimated the overall damage associated with the attacks at approximately CHF 100 million.

The defendant claimed he was working as an IT security consultant and was unaware that his software would be used for criminal purposes. The court rejected that explanation, noting that investigators had also discovered extortion messages among his data. The sentence exceeded the prosecution's request for a 12-year prison term. The judgment is not yet final however and can be appealed.

Conti ransomware member sentenced to 4 years by U.S. federal court

A U.S. federal court has sentenced Ukrainian national Oleksii Oleksiyovych Lytvynenko to four years in prison for his involvement in the Conti ransomware operation, one of the most prolific ransomware groups of recent years.

According to the U.S. Department of Justice (DOJ), the 44-year-old pleaded guilty in June 2026 to conspiracy to commit wire fraud. Lytvynenko participated in Conti operations as both an intruder and malware developer. Investigators found data stolen from eight U.S. victims and four victims outside the United States in his online accounts. He also admitted working on a malware "loader" used to facilitate further malicious activity.

Conti ransomware was used between 2020 and 2022 to attack more than 1,000 victims worldwide, including businesses, government organizations and critical infrastructure. The campaign affected organizations across 47 U.S. states and 31 foreign countries. The FBI estimated that Conti-related ransom payments exceeded $150 million by January 2022.

Lytvynenko was arrested in County Cork, Ireland, in July 2023 and subsequently extradited to the United States. Forensic evidence recovered during his arrest also indicated that he remained involved in ransomware activity after the Conti operation ended. The court has reserved its determination of restitution, which is expected to be finalized by November 16, 2026.

ImmuniWeb Newsletter

Get Cybercrime Weekly, invitations to our events and webinars in your inbox:


Private and Confidential Your data will stay private and confidential

Five Black Axe leaders extradited to United Staes

Five alleged leaders of the Black Axe transnational criminal organization have been extradited from South Africa to the United States to face federal charges related to internet fraud and money laundering schemes.

According to the U.S. Department of Justice (DOJ), Perry Osagiede, Franklyn Edosa Osagiede, Osariemen Eric Clement, Collins Owhofasa Otughwor and Musa Mudashiru were extradited on September 11, 2026. All five allegedly held leadership positions within the Cape Town branch of Black Axe and were arrested in South Africa in 2021 at the request of U.S. authorities. They appeared before a federal court in Trenton, New Jersey, on September 14.

Federal prosecutors allege that between 2011 and 2021 the defendants participated in widespread cyber-enabled fraud, including romance scams and advance-fee schemes. The group allegedly used social media, dating platforms, false identities and internet-based telephone services to establish relationships with U.S. victims and persuade them to transfer money or other valuables. Prosecutors also accuse the group of laundering proceeds obtained through business email compromise attacks.

South African authorities said the broader extradition operation involved six Nigerian nationals allegedly connected to Black Axe and that more than 100 U.S. women were targeted, with reported losses exceeding R100 million. The transfer was coordinated by South Africa's Hawks and INTERPOL with the FBI and U.S. Secret Service.

The five defendants face charges including wire fraud conspiracy and money laundering conspiracy, while several also face substantive wire fraud and aggravated identity theft charges. The allegations have not been proven, and the defendants are presumed innocent unless convicted.

ImmuniWeb can help you to prevent data breaches and meet regulatory requirements.

Three Ukrainian nationals facing charges for stealing 610,000 Roblox accounts

Ukrainian prosecutors have sent to court a case against three residents of Drohobych accused of illegally obtaining access to more than 610,000 accounts on the Roblox gaming platform and selling compromised accounts through Russian online resources.

According to Ukraine's Office of the Prosecutor General, the alleged operation was organized by a 19-year-old who recruited two 22-year-old associates. Between May 2025 and April 2026, the group allegedly obtained stolen session tokens, or cookies, that enabled access to Roblox accounts without entering the users' passwords. Special software was then used to verify the compromised accounts and identify those containing virtual currency, rare items and other valuable digital assets.

Investigators discovered 357 files containing information associated with more than 610,000 Roblox accounts. Prosecutors allege that valuable accounts were sold individually, while others were offered in bulk or at discounted prices through Russian websites and Telegram channels. Payments were received in cryptocurrency. The potential proceeds from selling all compromised accounts were estimated at more than UAH 20 million.

Authorities also allege that the defendants converted cryptocurrency into Ukrainian hryvnias and transferred the funds to their bank accounts, laundering nearly UAH 2.4 million. The operation was disrupted in April 2026, and all three defendants remain in custody. They face charges including theft, money laundering, unauthorized interference with information systems and illegal sale of restricted information.

What’s next:

Talk to an Expert