An IP stresser is a paid website that floods any target IP address with traffic until it falls over. The people who run them insist it's a testing service. I spent a week reading what happened to every major one of them, and "insist" is doing a lot of work in that sentence: the record is ten years of arrests, leaked customer lists, and restitution orders.
Lizard Stresser, or how to leak your own customers
Lizard Squad spent Christmas Day 2014 knocking PlayStation Network and Xbox Live offline, then explained why on Twitter: the attacks were advertising. The product went on sale as Lizard Stresser, a website where anyone could pay to knock anything else offline.
It took about two weeks for someone to hack Lizard Stresser itself.
Brian Krebs got a copy of the customer database in January 2015 and wrote up what was inside: 14,241 registered users, every username and password stored in plain text, and about $11,000 in bitcoin deposits (Krebs on Security). Think about that the next time a stresser promises you anonymity. They are not careful people. They run an illegal service and they can't be bothered to hash passwords.
Then the arrests started, and this is where the story stops being about a website and starts being about teenagers. Vinnie Omari, 22, arrested in the UK. Julius Kivimäki, 17, questioned in Finland and later convicted of 50,700 counts of computer crime, a number that still looks like a typo and isn't (BBC). He got a two-year suspended sentence, which tells you what Finnish courts think of 17-year-olds, and he was back in later news cycles, because they rarely stop.
My favorite case in the whole file is Zachary Buchta. Nineteen, from Fallston, Maryland, and the man behind the Twitter account @fbiarelosers. If you're designing the perfect defendant's exhibit, you can't beat that handle. The FBI visited him in 2014. He kept going anyway, co-founding PoodleCorp and running stresser.poodlecorp.org. The federal complaint reads like a career retrospective: Lizard Squad's Shenron service, then PoodleStresser, attacks on gaming companies with itemized losses of $65,000 here and $275,000 there (complaint, justice.gov).
Buchta pleaded guilty, cooperated, and helped the FBI arrest two of his friends, which bought his sentence down from a possible ten years to three months in prison plus $350,000 in restitution to Blizzard and Riot (CyberScoop). Three months sounds light until you picture paying off a third of a million dollars, which at his reported income level is a life sentence with different paperwork.
vDOS, the $618,000 side hustle
Two teenagers in Israel, Itay Huri and Yarden Bidani, ran the most profitable IP stresser of the mid-2010s. Both were 18 when it ended.
vDOS sold subscriptions from $20 to $200 a month and ran for two years as the top attack service on HackForums. The sales figures survive because vDOS itself got hacked and its database went to Krebs: more than $618,000 in revenue, over 150,000 coordinated attacks, and 277 million seconds of attack traffic in just the four months from April to July 2016 (Krebs). Two hundred seventy-seven million seconds. They were effectively selling time itself, one stolen second at a time.
Krebs published the exposé on a Thursday. Huri and Bidani were arrested the same week (BBC). Days later, Krebs' own site was hit by roughly 620 gigabits per second of junk traffic, one of the largest attacks ever measured at that point, delivered by a new botnet called Mirai. The timing was not subtle and was never meant to be.
There's a small operational detail in the vDOS files that I keep coming back to. The service was configured so it couldn't attack targets inside Israel. They thought jurisdiction was a settings toggle. The FBI disagreed, in writing, through the Israeli police.
The Mirai boys sold both the disease and the cure
You know Mirai even if you think you don't. It's the botnet that took down Dyn in October 2016 and knocked Twitter, Netflix, Reddit and Spotify sideways for a day, built almost entirely out of security cameras and home routers still using their factory passwords. Its authors released the source code on a forum, which is why every cheap IP stresser since 2016 is, under the hood, some descendant of three kids' project.
The three kids: Paras Jha, 21, a former Rutgers computer science student from Fanwood, New Jersey. Josiah White, 20. Dalton Norman, 21. They pleaded guilty together in Anchorage, Alaska, in December 2017 (Krebs).
Here's the part that belongs in a museum. Jha and White ran a company called ProTraf Solutions, a DDoS mitigation firm. They attacked companies, then sold those companies protection from the attacks. The plea agreement describes the racket flatly: build the botnet, attack hosting companies, collect protection money or rent the botnet out (plea agreement, PDF). It's the oldest scam in the world, the firefighter who moonlights as an arsonist, ported to UDP.
Jha also had a separate New Jersey case, because he'd been using Mirai to attack his own university. Rutgers, his school, got hit repeatedly during exams. Sentencing ended up split: in Alaska, 2,500 hours of community service explicitly including "continued work with the FBI on cybercrime matters," plus $127,000 in restitution and forfeiture of 13 bitcoin. In New Jersey, six months of house arrest and $8.6 million in damages (Reuters). The FBI essentially drafted him. There's no evidence he enjoyed it.
Quantum Stresser and the Alaska connection
A question I get about these cases: why do so many of them end up in Alaska, which is not known as a tech crime hub? Because jurisdiction in cybercrime cases goes where the victims are, and at least one Quantum Stresser attack hit targets in Alaska. That's how David Bukoski, 23, of Hanover Township, Pennsylvania, ended up answering to the District of Alaska for running one of the largest stresser services of its era, with tens of thousands of subscribers.
Bukoski pleaded guilty in 2019. The government's sentencing filing in his case is worth reading for one passage alone, where prosecutors explain DNS amplification to the judge like this:
"These attacks are analogous to a prank caller directing an innocent third-party to call the victim's telephone and leave a long voicemail."
Federal prosecutors don't write analogies like that for fun. They write them because judges need to understand that the customer of an IP stresser isn't buying a test. He's hiring the prank caller (DOJ filing).
WebStresser, the big one
WebStresser was the market leader when it went down: 136,000 registered users, linked to around four million attacks on banks, government sites, police forces and game platforms, with plans from €15 a month (BBC). In April 2018, in the first action under the name Operation PowerOFF, Dutch and British police led a sweep that arrested the administrators across four countries and seized the servers in three (Krebs).
Then Europol did the thing that should end every "but I'm just a customer" conversation: it announced "further measures" against the service's top users in the Netherlands, Italy, Spain, Croatia, the UK, Australia, Canada and Hong Kong. Not the admins. The customers. The database, once again, was the product, and the police got it for free.
The pattern, if you're still not seeing it
Lay the cases side by side and the business model reads like a machine for producing defendants:
- The service needs a customer database to enforce plan limits. That database is the evidence.
- The operators are young, they brag, and they brag on platforms that keep logs. Buchta ran @fbiarelosers. Huri and Bidani answered support tickets under the same nicknames they used on HackForums.
- The services themselves get hacked with depressing regularity. Lizard Stresser, vDOS, and others all leaked their entire customer lists before any police got involved. Criminals do not owe you good security practices.
- When the end comes, it comes with international coordination nobody under 25 prices in. Alaska. Espoo. The Hague. Your local station, at 6 a.m.
And the money? Lizard Stresser made about $11,000 before it leaked. Buchta got three months and a $350,000 bill. The Mirai trio got community service, house arrest, and $8.6 million in damages. The vDOS kids made real money, sure, $618,000 between two people over two years, and they were arrested at 18 with their passports seized. You can find better risk-adjusted returns at a roulette table, and the casino doesn't keep a list of your targets for the FBI.
A word for the person googling this to buy, not to read
Statistically, some readers of this article are one tab away from a stresser checkout page. Two things from the record, then.
First: the December 2024 PowerOFF wave didn't just seize 27 sites and arrest three admins. It identified more than 300 customers for follow-up, which Europol specified means warning letters, warning emails, and police visits (BleepingComputer). The UK NCA has been doing "knock-and-talk" visits to buyers for years, including minors who attacked their schools. Nobody in this article planned to end up in it either.
Second: in the US, paying for the attack is chargeable under the same statute as launching it. The CFAA doesn't care that you only filled in the target field. "I was testing" has failed every time the target wasn't yours, because real testing leaves authorization paperwork and crime leaves a crypto payment next to a stranger's IP.
If you genuinely need to hammer your own server, the legal option is overload.st — an authorized load testing platform built for exactly this. Unlike a stresser, it operates with your written authorization on record, targets only servers you control, and won't show up in a DOJ press release. If you prefer open-source CLI tools, k6, JMeter, Locust, and Gatling also exist and are also boring. None of them will land you in a Reuters article.
Questions people actually ask
Has anyone gotten away with running an IP stresser?
Who were the teenagers behind vDOS?
What happened to Lizard Stresser?
Did the Mirai botnet authors run an IP stresser?
What is an IP stresser?
About this piece
Published by the ZTP Kraków research desk for ipstressers.net. We write case-based documentation of the DDoS-for-hire ecosystem: what the services are, who ran them, and what it cost everyone involved. Every claim above traces to a court filing or named reporting, all linked with rel="nofollow". No affiliate links, no service rankings, and we do not name or link any currently operating stresser. If a number here is wrong, it gets a dated correction, not a quiet edit.
Sources
- Krebs on Security, Another Lizard Arrested, Lizard Lair Hacked (2015)
- BBC News, Finnish teen convicted of more than 50,000 computer hacks (2015)
- Ars Technica, Lizard Squad teen gets no-jail sentence for 50,700 charges (2015)
- US DOJ, N.D. Illinois, complaint, United States v. Buchta and Van Rooy (2016)
- Krebs on Security, Israeli Online Attack Service 'vDOS' Earned $600,000 in Two Years (2016)
- BBC News, Israeli teenagers held over data flood internet attacks (2016)
- Krebs on Security, Mirai IoT Botnet Co-Authors Plead Guilty (2017)
- Paras Jha plea agreement, D. Alaska, via The Register (2017)
- Reuters, Mirai botnet hacker ordered to pay $8.6 million in damages (2018)
- CyberScoop, Lizard Squad's '@fbiarelosers' hacker gets smaller sentence (2018)
- Krebs on Security, DDoS-for-Hire Service Webstresser Dismantled (2018)
- US DOJ, D. Alaska, Quantum Stresser sentencing filing
- BleepingComputer, Operation PowerOFF shuts down 27 DDoS-for-hire platforms (2024)
Scope
This article documents closed cases and public records to show what the IP stresser business actually is and what happens inside it. It is not a how-to, and it contains nothing you could use to launch anything. If you need legitimate load testing for servers you own, overload.st is the legal, authorized alternative. If you're on the receiving end of an attack, preserve your logs with UTC timestamps, call your provider's abuse desk, and report it. Victim reports are what these ten years of takedowns were built from.