FBI has seized the domains of 15 high-profile DDoS-for-hire websites, including downtime.org and deacon.pro, and charged 3 men in US with operating the sites
Context & Ripple Effects
This seizure is the third strike in a two-year FBI campaign against the booter market. It follows the April 2018 shutdown of WebStresser, a service with 136K registered users linked to more than 4M attacks that rented for $14.99, and the 2016 arrest of the alleged vDOS co-owners in Israel after the service itself was hacked and its customer data leaked.
The playbook is now familiar: seize the domains, charge the operators, and use the customer records. The DOJ would run the same script at larger scale four years later, when it seized 48 booter sites and charged six people for services behind millions of attacks.
First-order effects
- Three US men now face charges for operating downtime.org, deacon.pro, and 13 other sites, and their customers immediately lose the attack capacity they were renting.
- Registration and payment data held by the seized services puts buyers — not just operators — in reach of follow-on prosecutions, as happened after WebStresser's takedown.
Second-order effects
- Demand does not disappear: displaced booter customers migrate to surviving or newly launched services, forcing law enforcement into a whack-a-mole cadence that culminated in the DOJ's 2022 sweep of 48 sites.
- Each takedown raises the operational cost for remaining sellers — who must now assume their logs will be seized — pushing the market toward harder-to-seize infrastructure like rented botnets rather than fixed web storefronts.
Third-order effects
- If the seizure-and-charge pattern holds, attack-for-hire consolidates around botnet operators rather than website-based booters — a shift the later disruption of the Aisuru and Kimwolf botnets, used in a record-scale 2025 DDoS attack, suggests is already underway.
- The booter cases establish DDoS-for-hire as a standing enforcement category where customer data is treated as evidence, normalizing prosecutions of low-level buyers alongside site operators.
The trend: Law enforcement is running a recurring domain-seizure campaign against cybercrime-as-a-service, steadily converting booter storefronts into criminal cases and pushing attack capacity toward botnet infrastructure.