Alleged Kimwolf Botmaster ‘Dort’ Arrested, Charged in U.S. and Canada
Jacob Butler, a 23-year-old from Ottawa, Canada, was arrested for allegedly operating the Kimwolf IoT botnet, which enslaved millions of devices to conduct massive distributed denial-of-service (DDoS) attacks over six months. The botnet targeted devices like digital photo frames and web cameras, including those behind firewalls, and was involved in record-breaking DDoS attacks reaching nearly 30 Tbps. Butler faces criminal charges in both Canada and the U.S., including unauthorized computer use and aiding computer intrusion. Law enforcement seized Kimwolf's infrastructure along with other competing botnets. The botnet caused significant financial losses exceeding one million dollars for some victims and was linked to harassment campaigns such as doxing and swatting against security researchers. The investigation involved multiple agencies including the FBI and the Department of Defense. No specific software versions are identified as affected, and no patch or remediation is applicable as this concerns criminal activity rather than a software vulnerability.
AI Analysis
Technical Summary
The Kimwolf botnet, operated by Jacob Butler, was a large-scale Internet-of-Things botnet that enslaved millions of devices to conduct unprecedented DDoS attacks, including assaults on Department of Defense IP ranges. The botnet issued over 25,000 attack commands and was involved in financial damages exceeding one million dollars for some victims. Butler was identified through digital forensics linking IP addresses, online accounts, and transaction records. Law enforcement actions included seizure of botnet infrastructure and arrest of the alleged operator. The botnet exploited a critical security weakness in IoT devices to spread rapidly. Butler also engaged in harassment campaigns against security researchers. The case is under investigation by multiple U.S. and Canadian authorities, with criminal charges filed in both countries. There is no indication of a software vulnerability or patch; this is a criminal botnet operation.
Potential Impact
The Kimwolf botnet caused massive distributed denial-of-service attacks with volumes reaching nearly 30 terabits per second, resulting in significant financial losses for victims, some exceeding one million dollars. The botnet enslaved millions of IoT devices, including those traditionally firewalled from the internet, and was rented out to other cybercriminals. It also targeted critical infrastructure such as Department of Defense IP address ranges. Additionally, the botnet operator engaged in harassment activities including doxing and swatting of security researchers. The criminal activity disrupted internet services and posed risks to public and governmental networks.
Mitigation Recommendations
This threat pertains to criminal activity involving a botnet operator rather than a software vulnerability. Law enforcement has arrested the alleged operator and seized the botnet infrastructure. There is no patch or software remediation applicable. Organizations should continue to apply best practices for securing IoT devices and monitor for residual botnet activity. No direct mitigation actions are specified or required beyond ongoing law enforcement efforts.
Alleged Kimwolf Botmaster ‘Dort’ Arrested, Charged in U.S. and Canada
Description
Jacob Butler, a 23-year-old from Ottawa, Canada, was arrested for allegedly operating the Kimwolf IoT botnet, which enslaved millions of devices to conduct massive distributed denial-of-service (DDoS) attacks over six months. The botnet targeted devices like digital photo frames and web cameras, including those behind firewalls, and was involved in record-breaking DDoS attacks reaching nearly 30 Tbps. Butler faces criminal charges in both Canada and the U.S., including unauthorized computer use and aiding computer intrusion. Law enforcement seized Kimwolf's infrastructure along with other competing botnets. The botnet caused significant financial losses exceeding one million dollars for some victims and was linked to harassment campaigns such as doxing and swatting against security researchers. The investigation involved multiple agencies including the FBI and the Department of Defense. No specific software versions are identified as affected, and no patch or remediation is applicable as this concerns criminal activity rather than a software vulnerability.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The Kimwolf botnet, operated by Jacob Butler, was a large-scale Internet-of-Things botnet that enslaved millions of devices to conduct unprecedented DDoS attacks, including assaults on Department of Defense IP ranges. The botnet issued over 25,000 attack commands and was involved in financial damages exceeding one million dollars for some victims. Butler was identified through digital forensics linking IP addresses, online accounts, and transaction records. Law enforcement actions included seizure of botnet infrastructure and arrest of the alleged operator. The botnet exploited a critical security weakness in IoT devices to spread rapidly. Butler also engaged in harassment campaigns against security researchers. The case is under investigation by multiple U.S. and Canadian authorities, with criminal charges filed in both countries. There is no indication of a software vulnerability or patch; this is a criminal botnet operation.
Potential Impact
The Kimwolf botnet caused massive distributed denial-of-service attacks with volumes reaching nearly 30 terabits per second, resulting in significant financial losses for victims, some exceeding one million dollars. The botnet enslaved millions of IoT devices, including those traditionally firewalled from the internet, and was rented out to other cybercriminals. It also targeted critical infrastructure such as Department of Defense IP address ranges. Additionally, the botnet operator engaged in harassment activities including doxing and swatting of security researchers. The criminal activity disrupted internet services and posed risks to public and governmental networks.
Mitigation Recommendations
This threat pertains to criminal activity involving a botnet operator rather than a software vulnerability. Law enforcement has arrested the alleged operator and seized the botnet infrastructure. There is no patch or software remediation applicable. Organizations should continue to apply best practices for securing IoT devices and monitor for residual botnet activity. No direct mitigation actions are specified or required beyond ongoing law enforcement efforts.
Technical Details
- Article Source
- {"url":"https://krebsonsecurity.com/2026/05/alleged-kimwolf-botmaster-dort-arrested-charged-in-u-s-and-canada/","fetched":true,"fetchedAt":"2026-05-26T19:40:53.985Z","wordCount":1523}
Threat ID: 6a15f7466b9ae66727f4dbc2
Added to database: 05/26/2026, 19:40:54 UTC
Last enriched: 06/18/2026, 22:01:41 UTC
Last updated: 07/29/2026, 22:43:02 UTC
Views: 73
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.