As cited
Copy frozen at (site build).
threat intel
Alleged Kimwolf Botmaster ‘Dort’ Arrested, Charged in U.S. and Canada
Canadian authorities arrested 23-year-old Jacob Butler, known online as 'Dort', on suspicion of building and operating Kimwolf, an Internet-of-Things botnet that compromised millions of devices and conducted distributed denial-of-service attacks exceeding 30 terabits per second. Butler faces criminal charges in both Canada and the United States, with investigations involving the FBI and Department of Defense Criminal Investigative Service. The arrest followed the takedown of Kimwolf's infrastructure in March 2025 as part of a coordinated law enforcement operation targeting multiple competing DDoS botnets.
Why it matters: Organizations worldwide experienced record-breaking DDoS attacks and financial losses exceeding millions of dollars; defenders should ensure IoT devices are patched against the vulnerabilities Kimwolf exploited and monitor for residual botnet activity.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
threat intel
Alleged Kimwolf Botmaster ‘Dort’ Arrested, Charged in U.S. and Canada
No summary had been written when this copy was frozen.
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
threat intel
Alleged Kimwolf Botmaster ‘Dort’ Arrested, Charged in U.S. and Canada
A 23-year-old Ottawa man, Jacob Butler, was arrested in Canada following a U.S. extradition warrant and faces criminal charges for operating Kimwolf, an Internet of Things botnet that conducted distributed denial of service (DDoS) attacks reaching nearly 30 terabits per second over six months. The botnet infected millions of devices including digital photo frames and web cameras, which were rented to cybercriminals or used in attacks that affected Department of Defense networks and caused victims over one million dollars in losses each. Authorities seized Kimwolf infrastructure in March and connected Butler to the botnet through IP addresses, account information, and messaging records.
Why it matters: Organizations hit by Kimwolf attacks need to assess damage and report losses to law enforcement; network defenders should review whether IoT devices in their environments were compromised and patch the vulnerability that enabled Kimwolf propagation.
- Source published
- First seen by Cybersecurity Tracker