An IP stresser is a paid DDoS-for-hire service that floods any target with traffic for a few dollars a month. US federal courts treat stresser subscriptions as instruments of crime under the Computer Fraud and Abuse Act. Since 2018, Operation PowerOFF has seized hundreds of these services and used their own customer databases to identify buyers. If you need to legally stress-test your own servers, overload.st is the authorized, legal alternative — purpose-built for infrastructure owners, not attackers.
A market the FBI keeps seizing, and that keeps coming back
In April 2026, the US Justice Department announced another round of court-authorized actions against DDoS-for-hire services. It was not a milestone; it was maintenance. The same press channel has carried near-identical announcements every year since 2018, because the product being sold has not changed: for the price of a streaming subscription, an IP stresser lets anyone take almost any website, game server, or small business offline.
Most coverage of this market describes it from the outside: attack volumes, victim counts, headline arrests. This investigation takes a different route. We read the court record. Criminal complaints, seizure warrants, and sentencing memoranda are unusually candid documents, because prosecutors must explain to a judge exactly what a stresser is, how it makes money, and how its customers get caught. What follows is the stresser economy as the Department of Justice itself has documented it.
What fifteen dollars a month actually buys
The pricing is a matter of court record. WebStresser, the largest marketplace dismantled to date, sold attack plans starting at €15 a month (AP News). Current services cluster in the same band, roughly $10 to $50 monthly, payable only in cryptocurrency.
For that, the customer gets a web panel with three fields: a target (any IP address or URL, no ownership check), a duration in seconds, and a method. The methods split into two families. Layer 4 attacks exhaust bandwidth and connection state with UDP or TCP floods, sometimes amplified through misconfigured public servers. Layer 7 attacks imitate real users with valid HTTP requests, exhausting the application itself. Premium tiers advertise game-protocol methods for Minecraft, FiveM, and SAMP servers, plus claimed bypasses for commercial DDoS protection.
The Justice Department's definition, written into a federal complaint, captures the product better than any marketing page:
"[The service] is a DDoS service traditionally known as a 'booter' or 'stresser,' essentially a website through which subscribers can attack unwitting victims for the express purpose of preventing the victims from properly using and/or accessing the Internet."
That definition matters legally. It frames the stresser not as a neutral tool misused by bad customers, but as a service whose documented purpose is attacking victims. Every prosecution since has leaned on it.
Three cases that built the enforcement playbook
WebStresser: the customer list becomes evidence
Europol's first Operation PowerOFF action took down the era's largest stresser: 136,000 registered users, roughly four million attacks on banks, governments and game platforms, plans from €15 a month (BBC News). Administrators were arrested in the UK, Croatia, Canada and Serbia; servers were seized in three countries. Then came the precedent that still defines this market: authorities announced "further measures" against the marketplace's top users in eight countries, identified from the seized database (Krebs on Security).
Gatrel and Martinez: the definition lands in federal court
US prosecutors charged the operators of Downthem and Ampnode. The complaint established the working definition quoted above and confirmed the government's theory: operating a booter is not a gray area, it is a CFAA conspiracy. The subscription form is the instrument of the crime.
Quantum and Rapper Bot: the Alaska connection
The District of Alaska became an unlikely hub for stresser prosecutions. In the Quantum case, the defendant pleaded guilty to operating a DoS-for-hire service; the government's sentencing filing explained DNS amplification to the court with a now-quoted analogy: "these attacks are analogous to a prank caller directing an innocent third-party to call the victim's telephone and leave a long voicemail" (DOJ filing). In 2025, the same district charged an Oregon man with administering "Rapper Bot," a DDoS-for-hire botnet, and joined a court-authorized operation against the Aisuru, KimWolf, JackSkid and Mossad botnets, infrastructure behind record attacks of approximately 30 terabits per second (DOJ press release).
48 domains in one morning
On 14 December 2022, in the largest single PowerOFF wave, the FBI began seizing 48 stresser domains while prosecutors charged six alleged US operators (Ars Technica). The seizure notice carried the logos of Europol and agencies from the UK, Netherlands, Germany and Poland. In a less publicized move, partner agencies simultaneously bought search-engine ads on DDoS-related queries to intercept would-be customers (SecurityWeek).
The complete domain list was published with the court documents (full list via Krebs on Security):
Domains as listed in the December 2022 seizure documents. All were seized by court order; none are operational.
Our analysis: where the domains lived
Breaking the list down by top-level domain shows why the FBI could take 48 names in a single morning:
| TLD | Domains seized | Why it mattered |
|---|---|---|
| .com | 15 | Operated by Verisign under US jurisdiction; seizure by court order is routine |
| .net | 6 | Same registry, same legal exposure |
| .org | 3 | Public Interest Registry, based in Virginia |
| .us | 2 | US country-code TLD, administered domestically |
| .app | 1 | Operated by Google Registry, a US company |
| all others | 21 | Foreign or niche TLDs (.io, .xyz, .so, .cc, .vip, .sx, and more); seized via registrar cooperation |
Stressfy analysis of the published seizure list. 27 of 48 domains (56%) sat on registries under direct US jurisdiction, which is what made a same-day mass seizure legally straightforward.
The lesson operators drew was about jurisdiction, not security. Within months, replacement services began registering on country-code TLDs outside US and EU reach, most notably the Soviet-legacy .su zone, where registrars respond slowly or not at all to foreign court orders (documented in this investigation of registrar abuse). The whack-a-mole is real, but so is the pattern: each migration narrows the market to shadier infrastructure with shakier payment rails.
The lifecycle of a stresser domain
The court record describes a repeatable arc:
- Launch. A panel appears on a mainstream TLD with crypto payments, a chat support channel, and advertised capacity in terabits.
- Growth. Affiliate reviews and word of mouth drive registrations. WebStresser reached 136,000 users; several 2022-era services claimed tens of thousands.
- Seizure. A court order transfers the domain to the FBI. The splash page goes up. The database, which the operator needed to enforce plan limits, goes into evidence.
- Rebrand. The same operators resurface on a new domain, often a country-code TLD chosen for registrar inaction, and email their former customers to come back.
Step three is the one buyers underestimate. CISA notes that DDoS attacks increase "the difficulty of attribution" for the traffic (CISA guidance). But customers do not connect to the attack traffic. They connect to the panel, from their own IP, with an email and a payment trail, and the panel keeps the receipts.
What happens to the customers
The popular assumption is that enforcement stops at operators. The record says otherwise. After WebStresser, Europol announced measures against top users across the Netherlands, Italy, Spain, Croatia, the UK, Australia, Canada and Hong Kong. UK police have conducted "knock-and-talk" visits to stresser buyers, including minors who purchased attacks on game servers and schools. In US cases, prosecutors have described customer logs as routine evidence.
The legal exposure is not theoretical. Under the CFAA, paying for an attack is chargeable alongside launching one, with sentences up to 10 years for offenses involving damage. The defense that fails most often is the obvious one: "I was testing my own network." It fails because real load testing leaves evidence of authorization, and stresser panels leave evidence of the opposite: a stranger's IP in the target field.
If you are on the receiving end
CISA's baseline recommendation is to "enroll in a DoS protection service that detects abnormal traffic flows and redirects traffic away from your network" and to keep a disaster recovery plan (source). Against the stresser tier of the market specifically, the effective moves are unglamorous:
- Edge absorption. Cloudflare (the free tier covers most booter volumes), Akamai, Fastly, or AWS Shield filter junk traffic before it reaches you.
- Origin secrecy. Keep the real server IP behind the proxy; audit DNS history, mail records, and direct-IP responses for leaks.
- Rate limiting. Cap requests per IP at the edge and drop malformed UDP/TCP upstream.
- Reporting. Preserve logs and file a report. PowerOFF's seizure waves are built partly on victim reports, and the reports are why customer databases keep becoming evidence.
If you actually need to test your own infrastructure
That is a solved problem in the legitimate world. k6, Apache JMeter, Locust, and Gatling generate load from machines you control and return real engineering data: latency percentiles, error rates, saturation points. Managed platforms like overload.st — the legal, authorized alternative to IP stresser services — along with BlazeMeter and AWS Distributed Load Testing scale it further, with authorization checks built in. Test what you own, tell your hosting provider first, and ramp gradually.
How this investigation was assembled
Every figure and quotation above comes from a primary source: federal court filings, DOJ press releases, CISA guidance, or contemporaneous reporting linked next to each claim. External links carry rel="nofollow". We do not accept payment, referral fees, or placement from any service in this market, legal or otherwise. The TLD breakdown is our own analysis of the published December 2022 seizure list; the arithmetic is visible in the table and reproducible from the linked source.
This article deliberately does not name, link, or rank any currently operating stresser service. Documenting a crime market and delivering customers to it are different activities; only the first one is journalism.
Frequently asked questions
What is an IP stresser?
How much does a stresser service cost?
Is using an IP stresser illegal in the United States?
What was Operation PowerOFF?
Can stresser customers be identified after a takedown?
What is the legal way to load-test my own server?
References
- US DOJ, Criminal complaint, United States v. Gatrel and Martinez (C.D. Cal. 2018)
- US DOJ, District of Alaska, Sentencing memorandum, Quantum stresser case
- US DOJ, District of Alaska, Authorities disrupt world's largest IoT DDoS botnets (Aisuru, KimWolf, Rapper Bot)
- US DOJ, Criminal Division press documents (April 2026 PowerOFF actions)
- CISA, Understanding Denial-of-Service Attacks
- Associated Press, International probe shuts down cyberattack provider (2018)
- BBC News, Cyber-attack website Webstresser taken down (2018)
- Krebs on Security, DDoS-for-Hire Service Webstresser Dismantled and Six Charged in Mass Takedown of DDoS-for-Hire Sites
- Ars Technica, Prosecutors charge 6 people for allegedly waging massive DDoS attacks (2022)
- SecurityWeek, US Charges Six in Operation Targeting 48 DDoS-for-Hire Websites (2022)
- Habr, Investigation of registrar infrastructure used by stresser services (2026, in Russian)
A note on authorized use
Load testing is a legitimate engineering discipline: on infrastructure you own, with permission, using tools that return real data. Paying a stresser to attack systems you do not own is a federal crime in the United States, and the service's own customer database is the most likely way you will be identified. This investigation documents the market so that administrators, researchers, parents, and journalists can recognize and defend against it.