Global Takedown of NightmareStresser DDoS-for-Hire Service
Law enforcement agencies, led by the U.S. Department of Justice and the FBI via "Operation PowerOFF," have dismantled NightmareStresser, a prominent DDoS-for-hire "booter" service. Active since 2022, the platform provided scalable, low-cost distributed denial-of-service capabilities through a web-based "rent-a-bot" model. The operation successfully neutralized the service's operational infrastructure by seizing primary domains, including nightmare-stresser.com and nightmarestresser.org, thereby disrupting the Command and Control (C2) panels and integrated payment gateways used to facilitate volumetric attacks. This takedown mitigates a significant threat to government, educational, and gaming sectors that were subject to hundreds of thousands of facilitated attacks globally.
TeamPCP: Open-Source Software Supply Chain Campaign
A joint international operation led by the Australian Federal Police (AFP), the FBI, and the Western Australia Police Force (WAPF) has resulted in the arrest of two key members of the TeamPCP cybercrime group. The group specialized in high-impact supply chain attacks by injecting malicious code into widely utilized open-source software repositories. This technique facilitated large-scale credential theft, successfully exfiltrating over 500,000 user and organizational credentials from a global victim base. The arrests target Ruben Thomson, the alleged group leader, and Louis Gaebler, marking a significant disruption to a major global threat actor responsible for one of the most damaging hacking campaigns of the current year.
Global Takedown of the Sality P2P Botnet
On August 31, 2026, an international law enforcement and private sector operation successfully neutralized the Sality botnet, a resilient Peer-to-Peer (P2P) malware infrastructure active for over two decades. Led by the US Department of Justice and supported by Europol and CrowdStrike, the operation utilized specialized P2P node poisoning and sinkholing techniques to dismantle the botnet's decentralized command-and-control (C2) architecture. The botnet, linked to Russian-based malicious operations, infected over 11 million IP addresses globally, serving as a primary distribution hub for diverse payloads including ransomware, info-stealers, and loaders across multiple operating systems.