Lizard Squad's DDoS attack service “Lizard Stresser” runs mostly on thousands of hacked home routers
Brian Krebs / Krebs on Security :
Context & Ripple Effects
Lizard Squad spent late December 2014 knocking Xbox Live and PlayStation Network offline — coverage traced the group behind the attacks that crippled both networks — then monetized the notoriety by launching Lizard Stresser, a DDoS-for-hire service priced from $6 to $500 that the group openly called a marketing scheme for its earlier outages.
Brian Krebs' new reporting supplies the missing infrastructure story: the booter's firepower comes mostly from thousands of hijacked home routers, meaning paying customers are renting botnets built from ordinary consumers' hardware rather than any dedicated attack platform.
First-order effects
- Home router owners are the immediate victims: their devices are conscripted into Lizard Stresser's attack fleet without their knowledge, while buyers get cheap denial-of-service capacity sourced from consumer gear.
- The finding undercuts Lizard Squad's framing of the service as a legitimate stress-testing tool — Krebs' exposure ties the product directly to criminal use of stolen bandwidth.
Second-order effects
- Operating a customer-listed booter carries its own risk: within weeks, LizardStresser itself was hacked and its customer details made public, turning the buyer base into exposed targets.
- Krebs' identification of the hacked-router supply chain gives ISPs and security researchers a concrete detection target, pressuring the service's capacity base at its source.
Third-order effects
- The pattern — celebrity hacker groups converting outage stunts into subscription attack services running on unsecured consumer routers — foreshadows the commercial booter market that law enforcement later dismantled, as when WebStresser was shut down in 2018 after linking to millions of attacks.
- If home routers remain the default raw material for DDoS-for-hire, responsibility for mitigation shifts toward device makers and ISPs to secure consumer hardware by default.
The trend: DDoS-for-hire is industrializing around compromised consumer routers, turning unsecured home networking hardware into rentable attack infrastructure.