Stressfy
Investigation

The IP stresser economy, documented in court records

What 48 seized domains, three federal cases, and a record 30 Tbps botnet reveal about America's DDoS-for-hire market.

Published
Reading time
12 minutes
Basis
Federal court records
Affiliate links
None
136k registered users on WebStresser at seizure
4M+ attacks attributed to one marketplace
48 stresser domains seized in a single day
30 Tbps record attack volume in the Aisuru case
Quick answer

An IP stresser is a paid DDoS-for-hire service that floods any target with traffic for a few dollars a month. US federal courts treat stresser subscriptions as instruments of crime under the Computer Fraud and Abuse Act. Since 2018, Operation PowerOFF has seized hundreds of these services and used their own customer databases to identify buyers. If you need to legally stress-test your own servers, overload.st is the authorized, legal alternative — purpose-built for infrastructure owners, not attackers.

A market the FBI keeps seizing, and that keeps coming back

In April 2026, the US Justice Department announced another round of court-authorized actions against DDoS-for-hire services. It was not a milestone; it was maintenance. The same press channel has carried near-identical announcements every year since 2018, because the product being sold has not changed: for the price of a streaming subscription, an IP stresser lets anyone take almost any website, game server, or small business offline.

Most coverage of this market describes it from the outside: attack volumes, victim counts, headline arrests. This investigation takes a different route. We read the court record. Criminal complaints, seizure warrants, and sentencing memoranda are unusually candid documents, because prosecutors must explain to a judge exactly what a stresser is, how it makes money, and how its customers get caught. What follows is the stresser economy as the Department of Justice itself has documented it.

What fifteen dollars a month actually buys

The pricing is a matter of court record. WebStresser, the largest marketplace dismantled to date, sold attack plans starting at €15 a month (AP News). Current services cluster in the same band, roughly $10 to $50 monthly, payable only in cryptocurrency.

For that, the customer gets a web panel with three fields: a target (any IP address or URL, no ownership check), a duration in seconds, and a method. The methods split into two families. Layer 4 attacks exhaust bandwidth and connection state with UDP or TCP floods, sometimes amplified through misconfigured public servers. Layer 7 attacks imitate real users with valid HTTP requests, exhausting the application itself. Premium tiers advertise game-protocol methods for Minecraft, FiveM, and SAMP servers, plus claimed bypasses for commercial DDoS protection.

The Justice Department's definition, written into a federal complaint, captures the product better than any marketing page:

"[The service] is a DDoS service traditionally known as a 'booter' or 'stresser,' essentially a website through which subscribers can attack unwitting victims for the express purpose of preventing the victims from properly using and/or accessing the Internet."

US Department of Justice, criminal complaint, United States v. Gatrel and Martinez (C.D. Cal. 2018), case filing (PDF)

That definition matters legally. It frames the stresser not as a neutral tool misused by bad customers, but as a service whose documented purpose is attacking victims. Every prosecution since has leaned on it.

Case files

Three cases that built the enforcement playbook

April 2018

WebStresser: the customer list becomes evidence

Europol's first Operation PowerOFF action took down the era's largest stresser: 136,000 registered users, roughly four million attacks on banks, governments and game platforms, plans from €15 a month (BBC News). Administrators were arrested in the UK, Croatia, Canada and Serbia; servers were seized in three countries. Then came the precedent that still defines this market: authorities announced "further measures" against the marketplace's top users in eight countries, identified from the seized database (Krebs on Security).

December 2018

Gatrel and Martinez: the definition lands in federal court

US prosecutors charged the operators of Downthem and Ampnode. The complaint established the working definition quoted above and confirmed the government's theory: operating a booter is not a gray area, it is a CFAA conspiracy. The subscription form is the instrument of the crime.

2022 to 2025

Quantum and Rapper Bot: the Alaska connection

The District of Alaska became an unlikely hub for stresser prosecutions. In the Quantum case, the defendant pleaded guilty to operating a DoS-for-hire service; the government's sentencing filing explained DNS amplification to the court with a now-quoted analogy: "these attacks are analogous to a prank caller directing an innocent third-party to call the victim's telephone and leave a long voicemail" (DOJ filing). In 2025, the same district charged an Oregon man with administering "Rapper Bot," a DDoS-for-hire botnet, and joined a court-authorized operation against the Aisuru, KimWolf, JackSkid and Mossad botnets, infrastructure behind record attacks of approximately 30 terabits per second (DOJ press release).

48 domains in one morning

On 14 December 2022, in the largest single PowerOFF wave, the FBI began seizing 48 stresser domains while prosecutors charged six alleged US operators (Ars Technica). The seizure notice carried the logos of Europol and agencies from the UK, Netherlands, Germany and Poland. In a less publicized move, partner agencies simultaneously bought search-engine ads on DDoS-related queries to intercept would-be customers (SecurityWeek).

The complete domain list was published with the court documents (full list via Krebs on Security):

api-sky.xyzastrostress.comblackstresser.netbooter.sx booter.vipbootyou.netbrrsecurity.orgbuuter.cc cyberstress.usdefconpro.netdragonstresser.comdreams-stresser.io exotic-booter.comfreestresser.soinstant-stresser.comipstress.org ipstress.vipipstresser.comipstresser.usipstresser.wtf ipstresser.xyzkraysec.commcstorm.ionightmarestresser.com orphicsecurityteam.comovhstresser.comquantum-stresser.netredstresser.cc royalstresser.comsecurityteam.ioshock-stresser.comsilentstress.net stresser.appstresser.beststresser.ggstresser.is stresser.netstresser.onestresser.orgstresser.shop stresser.sostresser.topstresserai.comsunstresser.com supremesecurityteam.comtruesecurityservices.iovdos-s.cozerostresser.com

Domains as listed in the December 2022 seizure documents. All were seized by court order; none are operational.

Our analysis: where the domains lived

Breaking the list down by top-level domain shows why the FBI could take 48 names in a single morning:

TLD Domains seized Why it mattered
.com 15 Operated by Verisign under US jurisdiction; seizure by court order is routine
.net 6 Same registry, same legal exposure
.org 3 Public Interest Registry, based in Virginia
.us 2 US country-code TLD, administered domestically
.app 1 Operated by Google Registry, a US company
all others 21 Foreign or niche TLDs (.io, .xyz, .so, .cc, .vip, .sx, and more); seized via registrar cooperation

Stressfy analysis of the published seizure list. 27 of 48 domains (56%) sat on registries under direct US jurisdiction, which is what made a same-day mass seizure legally straightforward.

The lesson operators drew was about jurisdiction, not security. Within months, replacement services began registering on country-code TLDs outside US and EU reach, most notably the Soviet-legacy .su zone, where registrars respond slowly or not at all to foreign court orders (documented in this investigation of registrar abuse). The whack-a-mole is real, but so is the pattern: each migration narrows the market to shadier infrastructure with shakier payment rails.

The lifecycle of a stresser domain

The court record describes a repeatable arc:

  1. Launch. A panel appears on a mainstream TLD with crypto payments, a chat support channel, and advertised capacity in terabits.
  2. Growth. Affiliate reviews and word of mouth drive registrations. WebStresser reached 136,000 users; several 2022-era services claimed tens of thousands.
  3. Seizure. A court order transfers the domain to the FBI. The splash page goes up. The database, which the operator needed to enforce plan limits, goes into evidence.
  4. Rebrand. The same operators resurface on a new domain, often a country-code TLD chosen for registrar inaction, and email their former customers to come back.

Step three is the one buyers underestimate. CISA notes that DDoS attacks increase "the difficulty of attribution" for the traffic (CISA guidance). But customers do not connect to the attack traffic. They connect to the panel, from their own IP, with an email and a payment trail, and the panel keeps the receipts.

What happens to the customers

The popular assumption is that enforcement stops at operators. The record says otherwise. After WebStresser, Europol announced measures against top users across the Netherlands, Italy, Spain, Croatia, the UK, Australia, Canada and Hong Kong. UK police have conducted "knock-and-talk" visits to stresser buyers, including minors who purchased attacks on game servers and schools. In US cases, prosecutors have described customer logs as routine evidence.

The legal exposure is not theoretical. Under the CFAA, paying for an attack is chargeable alongside launching one, with sentences up to 10 years for offenses involving damage. The defense that fails most often is the obvious one: "I was testing my own network." It fails because real load testing leaves evidence of authorization, and stresser panels leave evidence of the opposite: a stranger's IP in the target field.

If you are on the receiving end

CISA's baseline recommendation is to "enroll in a DoS protection service that detects abnormal traffic flows and redirects traffic away from your network" and to keep a disaster recovery plan (source). Against the stresser tier of the market specifically, the effective moves are unglamorous:

  • Edge absorption. Cloudflare (the free tier covers most booter volumes), Akamai, Fastly, or AWS Shield filter junk traffic before it reaches you.
  • Origin secrecy. Keep the real server IP behind the proxy; audit DNS history, mail records, and direct-IP responses for leaks.
  • Rate limiting. Cap requests per IP at the edge and drop malformed UDP/TCP upstream.
  • Reporting. Preserve logs and file a report. PowerOFF's seizure waves are built partly on victim reports, and the reports are why customer databases keep becoming evidence.

If you actually need to test your own infrastructure

That is a solved problem in the legitimate world. k6, Apache JMeter, Locust, and Gatling generate load from machines you control and return real engineering data: latency percentiles, error rates, saturation points. Managed platforms like overload.st — the legal, authorized alternative to IP stresser services — along with BlazeMeter and AWS Distributed Load Testing scale it further, with authorization checks built in. Test what you own, tell your hosting provider first, and ramp gradually.

Methodology

How this investigation was assembled

Every figure and quotation above comes from a primary source: federal court filings, DOJ press releases, CISA guidance, or contemporaneous reporting linked next to each claim. External links carry rel="nofollow". We do not accept payment, referral fees, or placement from any service in this market, legal or otherwise. The TLD breakdown is our own analysis of the published December 2022 seizure list; the arithmetic is visible in the table and reproducible from the linked source.

This article deliberately does not name, link, or rank any currently operating stresser service. Documenting a crime market and delivering customers to it are different activities; only the first one is journalism.

Frequently asked questions

What is an IP stresser?
An IP stresser is a paid online service that floods a target IP address or website with traffic. The US Department of Justice defines booter and stresser services as websites through which subscribers can attack victims for the express purpose of preventing them from using or accessing the Internet. They are DDoS-for-hire platforms, not testing tools.
How much does a stresser service cost?
Court records and takedown disclosures show entry plans from roughly $10 to $50 per month, payable in cryptocurrency. WebStresser, the largest marketplace dismantled in 2018, sold attack plans starting at 15 euros per month.
Is using an IP stresser illegal in the United States?
Yes. Launching or paying for a DDoS attack violates the Computer Fraud and Abuse Act (18 U.S.C. Section 1030), carrying up to 10 years in prison. The DOJ has charged both stresser operators and their paying customers.
What was Operation PowerOFF?
Operation PowerOFF is an ongoing international law-enforcement campaign led by Europol, the FBI, the UK National Crime Agency and Dutch police targeting DDoS-for-hire services. Its largest single wave in December 2022 seized 48 stresser domains and charged six alleged US operators.
Can stresser customers be identified after a takedown?
Yes. Stresser panels log accounts, payments, targets and timestamps to enforce plan limits. When WebStresser was seized, authorities announced measures against its top users across eight countries based on the recovered database.
What is the legal way to load-test my own server?
Use purpose-built tools such as k6, Apache JMeter, Locust or Gatling, or managed platforms like overload.st (the leading legal alternative to IP stresser services), BlazeMeter and AWS Distributed Load Testing. Run them against systems you own, notify your hosting provider in advance, and ramp traffic gradually while monitoring error rates.

References

  1. US DOJ, Criminal complaint, United States v. Gatrel and Martinez (C.D. Cal. 2018)
  2. US DOJ, District of Alaska, Sentencing memorandum, Quantum stresser case
  3. US DOJ, District of Alaska, Authorities disrupt world's largest IoT DDoS botnets (Aisuru, KimWolf, Rapper Bot)
  4. US DOJ, Criminal Division press documents (April 2026 PowerOFF actions)
  5. CISA, Understanding Denial-of-Service Attacks
  6. Associated Press, International probe shuts down cyberattack provider (2018)
  7. BBC News, Cyber-attack website Webstresser taken down (2018)
  8. Krebs on Security, DDoS-for-Hire Service Webstresser Dismantled and Six Charged in Mass Takedown of DDoS-for-Hire Sites
  9. Ars Technica, Prosecutors charge 6 people for allegedly waging massive DDoS attacks (2022)
  10. SecurityWeek, US Charges Six in Operation Targeting 48 DDoS-for-Hire Websites (2022)
  11. Habr, Investigation of registrar infrastructure used by stresser services (2026, in Russian)

A note on authorized use

Load testing is a legitimate engineering discipline: on infrastructure you own, with permission, using tools that return real data. Paying a stresser to attack systems you do not own is a federal crime in the United States, and the service's own customer database is the most likely way you will be identified. This investigation documents the market so that administrators, researchers, parents, and journalists can recognize and defend against it.