Explainers

What is a Booter 2026 - How Booter Services Actually Work

A booter is a DDoS-for-hire service that sells attack traffic to anyone with a credit card. Learn how booters work, why they are illegal, and how to stay safe.

8 min readVerified security research

A booter is a website that rents out DDoS attacks as a subscription service. The customer pays, types in a target IP address, and the service floods that target with traffic until it goes offline. No technical skill required, no questions asked.

Booters market themselves as stressers, borrowing the name of legitimate network testing tools to look legal. The difference is verification. A real stresser requires proof that you own the target. A booter accepts any target on the internet, which is precisely what makes it a crime service.

The industry calls this model DDoS-for-hire. Researchers estimate the market at thousands of active panels, most of them run by a small number of operators who rebrand and reopen after every police seizure.


How a Booter Panel Works

The technical stack behind a booter is surprisingly ordinary, which is part of why they keep reappearing after takedowns.

  • The web panelA storefront with signup, subscription tiers, and a single input field for the target. Most panels are built from leaked or resold templates, which is why so many look identical.
  • The attack backendA botnet of infected devices, rented amplification servers, or a mix of both. The panel is only a cashier; the traffic comes from infrastructure the operator rents or controls.
  • Payment processingCryptocurrency is standard because card processors ban these services. Some panels resell access through API keys so other booters can white-label the same botnet.
  • Zero verificationThe defining trait. Any target, any time, no ownership check. This single design choice is what separates a crime service from a testing tool.

What These Panels Advertise

Court filings and security research give a consistent picture of booter pricing. The numbers below reflect what seized panels advertised, published here so defenders understand the economics of the threat.

Advertised plan Claimed power Typical price What buyers actually get
Basic 1 to 5 Gbps, short attacks $10 to $20 per month Shared botnet time, logged activity
Premium 10 to 50 Gbps, longer duration $50 to $100 per month Priority queue, still fully logged
VIP 100+ Gbps, API access $150+ per month Reseller rights, maximum legal exposure

Sources: public court documents from booter prosecutions and published security industry research.

The economics explain the demand: for the price of a streaming subscription, anyone can rent enough traffic to take a small business offline. They also explain the supply: one botnet can be resold to thousands of customers through dozens of rebranded panels.


Why Booters Are Illegal, and Why Users Get Caught

Attacking a network you do not own violates computer crime laws in virtually every jurisdiction. In the United States, the Computer Fraud and Abuse Act covers it. In the United Kingdom, the Computer Misuse Act. The European Union, Canada, Australia, and Brazil have equivalent statutes.

The part most customers miss is the evidence trail. A booter panel is a database of crimes, and it records everything: the email you registered with, the IP you connected from, the payment trail, and every target you attacked. When police seize the panel, and they keep seizing them, that database becomes a customer list for prosecutors.

The pattern repeats: Webstresser had 151,000 registered users when Europol seized it in 2018. Police then used its records to identify and visit customers across Europe, the US, and Australia. Every major seizure since has followed the same playbook.


If your goal is to know whether your own server survives heavy traffic, you do not need a booter. Legitimate stress testing tools exist, many of them free, and they produce better data than any panel.

  1. Read our main IP stresser guide to understand authorized, compliant testing.
  2. Check the best free stress testing tools if you have no budget.
  3. Follow the step by step legal guide before generating any traffic.
  4. If you are being attacked, our DDoS defense guide covers the mitigation layers that work.

Frequently Asked Questions

What is a booter service?

A booter is a DDoS-for-hire website that rents access to a botnet or attack infrastructure. Customers pay a subscription, type in any target IP address, and the service floods that target with traffic. Booters require no proof of ownership, which is what makes them illegal.

Are booter services illegal?

Yes. Operating a booter, paying for one, or using one against any target you do not own is a crime under laws such as the US Computer Fraud and Abuse Act and the UK Computer Misuse Act. Both operators and paying customers have been arrested and sentenced.

How do police find booter users?

When police seize a booter service, they seize its database. Booter panels log customer emails, payment details, source IP addresses, and every target attacked. Those logs have been used as evidence to identify and prosecute thousands of customers worldwide.

Is a booter the same thing as a stresser?

Booter operators use the word stresser as marketing cover. A legitimate stresser verifies that you own the target before generating traffic. A booter skips that check. Our stresser vs booter comparison breaks down the difference in detail.