Kimwolf Botmaster Jacob Butler Arrested on U.S. and Canada Charges

A 23-year-old Ottawa man faces U.S. and Canada charges for running the massive Kimwolf IoT botnet.

By Central
Jacob Butler, aka Dort, linked to record 30 Tbps DDoS attacks and harassment of security researchers.
Highlights
  • The Kimwolf botnet enslaved millions of IoT devices, including digital photo frames and web cameras.
  • Jacob Butler conducted swatting and doxing campaigns against security researcher Ben Brundage.
  • U.S. and Canadian authorities seized infrastructure for Kimwolf and three other DDoS botnets in March 2026.

Canadian authorities have arrested a 23-year-old Ottawa man for building and operating the Kimwolf botnet, an Internet-of-Things (IoT) botnet that enslaved millions of devices to conduct some of the largest distributed denial-of-service (DDoS) attacks on record. Jacob Butler, who operated under the alias “Dort,” now faces criminal charges in both Canada and the United States, including computer intrusion, mischief, and unauthorized use of a computer system. The suspect was publicly identified in February 2026 after launching a series of DDoS, doxing, and swatting campaigns against security researchers. The investigation involves the FBI field office in Anchorage and the Department of Defense’s Defense Criminal Investigative Service, as Kimwolf attacks specifically targeted internet address ranges belonging to the DoD.

Kimwolf Botnet: Record-Setting DDoS Attacks and Global Impact

The Kimwolf botnet distinguished itself by targeting devices traditionally firewalled from the internet, including digital photo frames and web cameras. According to the Department of Justice, Kimwolf was responsible for DDoS attacks measured at nearly 30 Terabits per second, a record in recorded attack volume. The botnet issued over 25,000 attack commands, causing financial losses exceeding one million dollars for some victims. In March 2026, U.S. authorities joined international law enforcement partners in seizing the technical infrastructure for Kimwolf and three other competing DDoS botnets named Aisuru, JackSkid, and Mossad. The government connected Butler to the botnet’s administration through IP address records, online account information, transaction records, and messaging application data obtained via legal process.

Harassment Campaign Targeting Security Researchers

Beyond its technical capabilities, the Kimwolf operation was marked by a sustained harassment campaign against individuals who worked to expose and disrupt the botnet. Butler claimed responsibility for at least two swatting attacks targeting the founder of Synthient, a security startup that helped secure a critical weakness Kimwolf exploited to spread faster than any other IoT botnet. The criminal complaint against Butler details how he ordered swatting attacks against Synthient’s founder, Ben Brundage, who stated he is relieved Butler is in custody. The complaint demonstrates that Butler made minimal effort to separate his real-life identity from his cybercriminal activities, a factor that aided investigators in tracking him down.

Butler was arrested by the Ontario Provincial Police pursuant to a U.S. extradition warrant and is currently in Canadian custody awaiting an initial court hearing scheduled for early next week. A search warrant executed at his Ottawa residence in March resulted in the seizure of multiple devices. In Canada, Butler faces charges of unauthorized use of computer, possession of device to obtain unauthorized use of computer system or to commit mischief, and mischief in relation to computer data. In the United States, he faces one count of aiding and abetting computer intrusion. If extradited, tried, and convicted in the U.S., Butler could face up to 10 years in prison, though sentencing guidelines may account for mitigating factors including his age and lack of prior criminal history.

Immediate Steps to Protect Against IoT Botnet Threats

While the arrest of a major botnet operator represents a significant law enforcement victory, the underlying vulnerabilities that enabled Kimwolf remain widespread. Organizations and individuals should take immediate action to secure Internet-of-Things devices. Change all default credentials on connected devices, disable Universal Plug and Play (UPnP) where it is not explicitly required, and segment IoT devices onto a separate network VLAN to limit the blast radius of a potential compromise. Deploy a reputable endpoint detection and response solution capable of identifying anomalous outbound traffic patterns associated with botnet command-and-control communication. Enable multi-factor authentication across all administrative accounts and ensure firmware is kept current. For organizations handling sensitive data, conducting a full inventory of connected devices and auditing network access controls are essential steps to reduce exposure to similar large-scale botnet threats.

Share This Article