# Kimwolf Botmaster "Dort" Arrested: Record-Breaking DDoS Campaign Dismantled


The alleged mastermind behind Kimwolf, one of the most destructive IoT botnets in recorded history, has been arrested and faces criminal charges in both the United States and Canada. Jacob Butler, a 23-year-old from Ottawa known in cybercriminal circles as "Dort," was taken into custody by the Ontario Provincial Police on Wednesday following a U.S. extradition warrant. Federal prosecutors unsealed a criminal complaint in Alaska district court charging Butler with operating the Kimwolf distributed denial-of-service (DDoS) botnet, which orchestrated attacks exceeding 30 terabits per second—a new record for DDoS attack volume.


The arrest marks a significant victory for international law enforcement and represents a turning point in the ongoing battle against large-scale cybercriminal infrastructure. It also brings potential relief to security researchers who became targets of harassment, doxing, and swatting attacks after publicly identifying Butler's real-world identity.


## The Threat: A Record-Breaking Botnet


Kimwolf emerged as one of the fastest-spreading Internet-of-Things botnets of 2025-2026, enslaving millions of consumer devices to conduct devastating cyberattacks. The botnet specialized in compromising internet-connected devices that were traditionally isolated behind firewalls—digital photo frames, webcams, smart home devices, and other IoT endpoints that rarely received security updates.


Key attack metrics:


| Metric | Details |

|--------|---------|

| Peak attack volume | 30+ terabits per second |

| Attack commands issued | Over 25,000 separate DDoS operations |

| Financial impact | Exceeded $1 million in losses for some victims |

| Targeted sectors | Internet infrastructure, Department of Defense IP ranges |

| Operational window | Six months of active exploitation |


Once compromised, infected devices were either rented to other cybercriminals for additional attack campaigns or conscripted into Kimwolf's own DDoS infrastructure. The botnet competed directly with three other large DDoS botnets—Aisuru, JackSkid, and Mossad—for access to the same pool of vulnerable devices, creating a criminal arms race in the DDoS-for-hire marketplace.


## Background and Context: From Anonymous Operator to Identified Threat


Butler maintained a low profile in cybercriminal forums until February 2026, when KrebsOnSecurity publicly identified him as "Dort" through investigative journalism. The publication's analysis traced Butler's various email addresses, forum registrations, posts on Telegram and Discord, and other digital breadcrumbs that collectively revealed his real-world identity despite his attempts at operational security.


What followed was a campaign of retaliation against the journalists and security researchers who had contributed to his identification. Butler was linked to swatting attacks—wherein false emergency calls are made to send armed police to someone's residence—targeting Ben Brundage, the founder of Synthient, a security firm that had discovered and helped patch critical vulnerabilities in Kimwolf's propagation mechanisms. Brundage and other researchers also faced persistent harassment and threats from the botmaster as the investigation tightened around him.


"Hopefully this will end the harassment," Brundage told KrebsOnSecurity upon learning of Butler's arrest.


## Technical Details: How Kimwolf Enslaved Devices


The Kimwolf botnet leveraged several critical vulnerabilities to achieve its rapid spread and unprecedented attack scale. The malware specifically targeted default credentials and unpatched security flaws in commonly deployed IoT devices. Unlike botnets that infected systems with sophisticated persistence mechanisms, Kimwolf optimized for rapid infection across low-security endpoints that manufacturers rarely updated and consumers rarely monitored.


Infection vectors included:


  • Exploitation of known vulnerabilities in camera firmware and network appliances
  • Brute-force attacks against devices using factory-default or weak credentials
  • Automated scanning of public IP ranges to identify vulnerable endpoints
  • Malware propagation through compromised network infrastructure

  • Once infected, victim devices became part of a distributed command-and-control (C2) infrastructure. Butler issued attack commands through internet-connected servers and messaging platforms, directing botnets to launch coordinated DDoS floods against specific targets. The attacks overwhelmed internet backbone infrastructure by consuming bandwidth at rates that paralyzed networks, rendered websites unreachable, and in some cases disrupted critical government communications.


    The scale was particularly notable: a 30-terabit-per-second attack represents an order of magnitude larger than the largest publicly documented DDoS attacks from previous years, underscoring the growing threat posed by compromised IoT deployments at scale.


    ## Investigation and Arrest: International Law Enforcement Response


    The investigation that ultimately led to Butler's arrest involved contributions from multiple agencies and organizations:


  • Defense Criminal Investigative Service (DCIS) — investigating attacks on Department of Defense IP ranges
  • FBI Anchorage field office — federal prosecution support
  • Department of Justice — coordinating international law enforcement
  • Ontario Provincial Police — arrest and custody
  • Technology companies — including Synthient, which patched the vulnerabilities Kimwolf exploited

  • On March 19, 2026, U.S. authorities coordinated with international partners to seize the technical infrastructure supporting Kimwolf and three competing botnets (Aisuru, JackSkid, and Mossad). The seizure disrupted the command infrastructure, rendering millions of enslaved devices temporarily unable to receive attack commands.


    The criminal complaint against Butler reveals minimal operational security. Butler conflated his personal and cybercriminal identities across multiple platforms, using consistent usernames, email addresses, and account recovery information that allowed investigators to build an irrefutable identity chain. Transaction records, IP address logs, and messaging application data obtained through legal process provided prosecutors with direct evidence linking Butler to botnet administration.


    ## Implications: Urgent Lessons for Network Defense


    The Kimwolf case illuminates critical gaps in IoT security across the internet ecosystem:


    For organizations:

  • IoT devices remain the lowest-hanging fruit for large-scale botnet recruitment, often accumulating unpatched vulnerabilities for years after deployment
  • Firewalled or isolated networks do not provide security if the devices themselves are compromised—network segmentation is necessary but insufficient without endpoint hardening
  • Organizations must implement network monitoring to detect anomalous outbound traffic from IoT endpoints

  • For critical infrastructure:

  • Department of Defense and other critical sectors remain vulnerable to attacks originating from compromised consumer devices, underscoring the interconnected nature of modern internet architecture
  • Botnets targeting critical infrastructure can be assembled from distributed consumer equipment, making attribution and prevention challenging

  • For manufacturers and ISPs:

  • Device manufacturers must implement automatic security updates or face regulatory scrutiny
  • Internet service providers should implement upstream DDoS mitigation and traffic filtering to reduce the amplification potential of compromised devices

  • ## Recommendations for Defenders


    Organizations and individuals can take concrete steps to reduce exposure:


    1. Audit IoT devices — Inventory all internet-connected devices, identify those with weak or default credentials, and change them immediately

    2. Apply firmware updates — Set automatic updates for all IoT devices or establish quarterly patching schedules

    3. Segment networks — Isolate IoT devices on separate VLANs from critical systems and user endpoints

    4. Monitor outbound traffic — Detect and alert on unusual bandwidth consumption or command-and-control communication patterns

    5. Disable unnecessary services — Disable remote administration, unnecessary open ports, and unused protocols on IoT endpoints

    6. Implement rate limiting — Deploy upstream DDoS mitigation and rate-limiting policies at network edges


    ## HackWire Analysis


    The arrest of Jacob Butler represents a critical inflection point in the botnet wars, but also exposes a uncomfortable truth: large-scale IoT botnets have become a viable criminal business model precisely because the barrier to entry remains so low. Butler was 23 years old, operating from Canada, and managed to command infrastructure responsible for the largest DDoS attacks in recorded history. The fact that he conflated his personal and cybercriminal identities so carelessly suggests he believed—until very recently—that he was operating with near-total impunity.


    What changed wasn't technology or law enforcement capability, but rather the decision by security researchers and journalists to shift from tracking the botnet to unmasking the operator. That investigative work—naming Butler publicly, drawing connections between his identities, and helping patch the vulnerabilities Kimwolf exploited—appears to have accelerated his arrest more than any single technical intervention.


    The larger concern: for every Dort arrested, thousands of similarly motivated operators are currently building the next botnet. The devices remain vulnerable. Manufacturers still release products with trivial-to-exploit weaknesses. ISP-level mitigation remains fragmented and inconsistent. Until IoT security becomes a baseline requirement rather than an afterthought, we should expect larger botnets, more expensive attacks, and an expanding surface for recruitment.


    The good news: this arrest proves that persistence and coordination across researchers, companies, and law enforcement can pierce the anonymity that cybercriminals rely on. The bad news: it required months of investigation for one 23-year-old. We have thousands of botnets in active operation globally.


    HackWire Editorial


    ## Related Coverage


  • Read more in our [Policy](https://www.hackwire.news/category/policy) coverage
  • Cross-reference with [Breaches](https://www.hackwire.news/category/breaches) and [Vulnerabilities](https://www.hackwire.news/category/vulnerabilities)
  • Stay current via the [HackWire homepage](https://www.hackwire.news/)