27 Distributed Denial of Service (DDoS) for hire platforms have been given the boot before they cause Christmas mayhem. Operation PowerOFF was led by Europol and supported by law enforcement in 15 countries worldwide.
Among those countries supporting this action were Australia, Brazil, Canada, Japan and the USA. European countries involved included the UK, France, Germany, Finland, Latvia, the Netherlands, Poland, Portugal, Sweden and Romania. There were also a number of technology vendors involved, including Akamai, Cloudflare, Flashpoint, Google, AWS and others.
The successful culmination of this year’s Operation PowerOFF saw zdstresser.net, orbitalstress.net and startstresser.net among the 27 websites taken down. Three administrators were arrested in France and Germany, and over 300 users of the services have been identified. They can expect to be targeted by law enforcement later.
In the US, the Department of Justice unveiled two indictments as part of this operation and the seizure of another domain, Securityhide.net. The first indictment was for Brazilian national Ricardo Cesar Colli, a.k.a. “TotemanGames.” He is accused of being the administrator of Securityhide.net. The second was for an unnamed individual who the US says it is working with partners to arrest.
Intelligence-led arrests
Planning for the event was coordinated by the European Cybercrime Centre (EC3). It spent a week running intensive technical sprints to develop investigative leads. The Joint Cybercrime Action Taskforce (J-CAT) provided analytical support and forensic assistance. It also assisted with the tracing of crypto used by the cybercriminals.
It is unclear how much crypto and infrastructure, including servers, was seized. Such seizures during previous operations have often yielded significant intelligence, which has led to further arrests and shutdowns.
While 300 users have already been identified, the question is, how many more names are going to be found? For users of these services, many will be looking over their shoulder, especially as email logs showing what they planned are examined.
In a release, the US Department of Justice stated, “The websites targeted in this operation were used to launch millions of actual or attempted DDoS attacks targeting victims worldwide.
“While some of these services claimed to offer stresser services that could purportedly be used for network testing, the FBI and DCIS determined these claims to be a pretense, and thousands of communications between booter site administrators and their customers…make clear that both parties are aware that the customer is not attempting to attack their own computers.”
UK’s National Crime Agency to launch Google Ads campaign
The UK’s NCA is already setting out what it sees happening next and how it intends to respond to the cybercrime threat. It notes that a large amount of evidence has been compiled on those using the sites. Those that are based in the UK can now expect to be targeted. Some will be arrested, and others will be warned about their involvement.
This is in line with existing policies and programmes. Prevent, for example, already sees the NCA contact people who they believe are on the edge of a cybercriminal career. The idea is that intervention is better than incarceration.
Operation PowerOFF has seen the NCA launch a Google ads campaign in the UK. It claims that the ads will reach thousands of people. One target is young people searching for DDoS-for-hire tools on Google. The ads will warn them not to use these services.
Frank Tutty, from the NCA’s National Cyber Crime Unit, said, “DDoS-for-hire services are a key component of cyber crime, and enable individuals with limited technical capability to offend with ease due to their ease of access and perceived anonymity. Operation PowerOFF helps to undermine trust in this criminal marketplace and make cyber criminals think twice before unleashing DDoS attacks, which can have serious consequences.
“We know that Booter services are an attractive entry-level cyber crime, and users can go on to even more serious offending. Therefore, tackling this threat doesn’t just involve arresting offenders, it includes steering people away from straying into cyber crime and helping them make the right cyber choices.
“This is why our Google ad campaign is such a crucial part of this overarching operation, preventing would-be offenders from engaging with them in the first place, in tandem with enforcement action undertaken by law enforcement partners around the world.”
Enterprise Times: What does this mean?
Operations like this are becoming increasingly commonplace as law enforcement agencies worldwide continue to cooperate. They disrupt cybergangs and, more importantly, help to target those at the bottom of the cybercrime chain. They also deliver significant intelligence for future operations.
Operation PowerOFF has successfully taken down 27 DDoS services and gained a lot of intelligence. That’s the good news. The hope is that they won’t be back online before the holidays.
However, one thing we have learned from the last few years is that cybercrime groups are more resilient than the majority of corporate networks. It won’t be long before backup sites appear and they rebuild these sites. The key is the intelligence gathered, taking away their funding and staying aware.

















