
Europol has introduced the takedown of distributed denial of service (DDoS)-for-hire companies that had been used to launch hundreds of cyber-attacks the world over.
In reference to the operation, Polish authorities have arrested 4 people and america has seized 9 domains which are related to the now-defunct platforms.
“The suspects are believed to be behind six separate stresser/booter companies that enabled paying clients to flood web sites and servers with malicious visitors — knocking them offline for as little as EUR 10,” Europol mentioned in a press release.
The companies, named cfxapi, cfxsecurity, neostress, jetstress, quickdown and zapcut, are mentioned to have been instrumental in launching widespread assaults on colleges, authorities companies, companies, and gaming platforms between 2022 and 2025.
Europol mentioned the platforms provided “slick consumer interfaces,” enabling malicious actors with little to no technical experience to orchestrate DDoS assaults by merely coming into a goal IP deal with, selecting the kind of assault, and paying a payment.
Stresser companies, usually marketed on underground boards, are sometimes disguised as professional stress-testing instruments however are designed to disrupt entry to internet assets by letting their clients unleash a flood of faux visitors in opposition to a goal website, making them inaccessible to actual customers.
“In contrast to conventional botnets, which require the management of huge numbers of contaminated units, stresser/booter companies industrialise DDoS assaults via centralised, rented infrastructure,” Europol famous.
In response to snapshots captured on the Web Archive, cfxsecurity, hosted on the domains cfxsecurity[.]wager and “cfxsecurity.cc,” marketed itself because the “#1 stress testing service” and that it supplied “complete stress take a look at, making certain your web site and companies are able to climate any storm.”
The service provided three plans, Starter for $20/month, Premium for $50/month, and Enterprise for $130/month. QuickDown (“quickdown[.]professional”), likewise, priced its package for wherever between $20/month to $379/month.
Cloud safety firm Radware, in a report revealed in August 2024, revealed that QuickDown is amongst a brand new crop of stresser companies which have adopted a hybrid structure combining each botnets and devoted servers. QuickDown is alleged to have launched a “Botnet addon and new plans associated to the Botnet community” in September 2023.
The newest motion, carried out in collaboration with Dutch and German authorities, is a part of an ongoing effort referred to as Operation PowerOFF that goals to dismantle infrastructure facilitating DDoS-for-hire exercise.
In December 2024, a set of 27 stresser companies had been taken offline, alongside asserting costs in opposition to six totally different people within the Netherlands and the U.S.