Canadian authorities on Wednesday arrested a 23-year-old Ottawa man on suspicion of constructing and working Kimwolf, a quick spreading Web-of-Issues botnet that enslaved hundreds of thousands of gadgets to be used in a sequence of huge distributed denial-of-service (DDoS) assaults over the previous six months. KrebsOnSecurity publicly named the suspect in February 2026 after the accused launched a volley of DDoS, doxing and swatting campaigns in opposition to this writer and a safety researcher. He now faces prison hacking fees in each Canada and the US.
A prison grievance unsealed as we speak in an Alaska district courtroom fees Jacob Butler, a.okay.a. “Dort,” of Ottawa, Canada with working the Kimwolf DDoS botnet. A assertion from the Division of Justice says the grievance in opposition to Butler was unsealed following the defendant’s arrest in Canada by the Ontario Provincial Police pursuant to a U.S. extradition warrant. Butler is presently in Canadian custody awaiting an preliminary courtroom listening to scheduled for early subsequent week.
The federal government stated Kimwolf focused contaminated gadgets which had been historically “firewalled” from the remainder of the web, equivalent to digital photograph frames and net cameras. The contaminated methods had been then rented to different cybercriminals, or pressured to take part in record-smashing DDoS assaults, in addition to assaults that affected Web deal with ranges for the Division of Protection. Consequently, the DoD’s Protection Legal Investigative Service is investigating the case, with help from the FBI area workplace in Anchorage.
“KimWolf was tied to DDoS assaults which had been measured at almost 30 Terabits per second, a file in recorded DDoS assault quantity,” the Justice Division assertion reads. “These assaults resulted in monetary losses which, for some victims, exceeded a million {dollars}. The KimWolf botnet is alleged to have issued over 25,000 assault instructions.”
On March 19, U.S. authorities joined worldwide legislation enforcement companions in seizing the technical infrastructure for Kimwolf and three different giant DDoS botnets — named Aisuru, JackSkid and Mossad — that had been all competing for a similar pool of susceptible gadgets.
On February 28, KrebsOnSecurity recognized Butler because the Kimwolf botmaster after digging by means of his numerous electronic mail addresses, registrations on the cybercrime boards, and posts to public Telegram and Discord servers. Nevertheless, Dort continued to threaten and harass researchers who helped monitor down his real-life identification and dramatically sluggish the unfold of his botnet.
Dort claimed duty for at the least two swatting assaults concentrating on the founding father of Synthient, a safety startup that helped to safe a widespread crucial safety weak spot that Kimwolf was utilizing to unfold quicker and extra successfully than every other IoT botnet on the market. Synthient was amongst many expertise corporations thanked by the Justice Division as we speak, and Synthient’s founder Ben Brundage informed KrebsOnSecurity he’s relieved Butler is in custody.
“Hopefully this can finish the harassment,” Brundage stated.
An excerpt from the prison grievance in opposition to Butler, detailing how he ordered a swatting assault in opposition to Ben Brundage, the founding father of the safety agency Synthient.
The federal government says investigators related Butler to the administration of the KimWolf botnet by means of IP deal with, on-line account data, transaction data, and on-line messaging utility data obtained by means of the issuance of authorized course of. The prison grievance in opposition to Butler (PDF) exhibits he did little to separate his real-life and cybercriminal identities (one thing we demonstrated in our February unmasking of Dort).
In April, the Justice Division joined authorities throughout Europe in seizing domains tied to almost four-dozen DDoS-for-hire companies, though due to a bureaucratic mix-up the record of seized domains has stay sealed till as we speak. The DOJ stated at the least a type of companies collaborated with Butler’s Kimwolf botnet.
An announcement from the Ontario Provincial Police stated a search warrant was executed on March 19 at Butler’s deal with in Ottawa, the place they seized a number of gadgets. On account of that investigation, Butler was arrested and charged this week with unauthorized person of pc; possession of machine to acquire unauthorized use of pc system or to commit mischief; and mischief in relation to pc knowledge. He’s scheduled to stay in custody till a listening to on Might 26.
In the US, Butler is going through one depend of aiding and abetting pc intrusion. If extradited, tried and convicted in a U.S. courtroom, Butler might withstand 10 years in jail, though that most sentence would doubtless be closely tempered by issues within the U.S. Sentencing Tips, which make allowances for mitigating elements equivalent to youth, lack of prison historical past and degree of cooperation with investigators.







