CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

Alleged Kimwolf Botmaster ‘Dort’ Arrested, Charged in U.S. and Canada

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 137

As cited

Copy frozen at (site build).

threat intel

Alleged Kimwolf Botmaster ‘Dort’ Arrested, Charged in U.S. and Canada

Canadian authorities arrested 23-year-old Jacob Butler, known online as 'Dort', on suspicion of building and operating Kimwolf, an Internet-of-Things botnet that compromised millions of devices and conducted distributed denial-of-service attacks exceeding 30 terabits per second. Butler faces criminal charges in both Canada and the United States, with investigations involving the FBI and Department of Defense Criminal Investigative Service. The arrest followed the takedown of Kimwolf's infrastructure in March 2025 as part of a coordinated law enforcement operation targeting multiple competing DDoS botnets.

Why it matters: Organizations worldwide experienced record-breaking DDoS attacks and financial losses exceeding millions of dollars; defenders should ensure IoT devices are patched against the vulnerabilities Kimwolf exploited and monitor for residual botnet activity.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

Alleged Kimwolf Botmaster ‘Dort’ Arrested, Charged in U.S. and Canada

No summary had been written when this copy was frozen.

First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

Alleged Kimwolf Botmaster ‘Dort’ Arrested, Charged in U.S. and Canada

A 23-year-old Ottawa man, Jacob Butler, was arrested in Canada following a U.S. extradition warrant and faces criminal charges for operating Kimwolf, an Internet of Things botnet that conducted distributed denial of service (DDoS) attacks reaching nearly 30 terabits per second over six months. The botnet infected millions of devices including digital photo frames and web cameras, which were rented to cybercriminals or used in attacks that affected Department of Defense networks and caused victims over one million dollars in losses each. Authorities seized Kimwolf infrastructure in March and connected Butler to the botnet through IP addresses, account information, and messaging records.

Why it matters: Organizations hit by Kimwolf attacks need to assess damage and report losses to law enforcement; network defenders should review whether IoT devices in their environments were compromised and patch the vulnerability that enabled Kimwolf propagation.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary