Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Anthropic Claude: New Security Feature Automates Agent Access Approvals
August 10, 2026
Critical Vulnerability Lets Attackers Bypass MFA in Windows 11 and Entra ID
August 10, 2026
Critical HP ThinPro TPM Flaw Exposes LUKS Disk Encryption Keys
August 10, 2026
Home/CyberSecurity News/Canadian Man Arrested for Operating KimWolf DDoS Botnet
CyberSecurity News

Canadian Man Arrested for Operating KimWolf DDoS Botnet

Key Takeaways A 23-year-old Canadian man has been arrested for allegedly operating the KimWolf DDoS botnet. KimWolf weaponized over a million IoT devices, including those on the U.S. Department of...

Sarah simpson
Sarah simpson
May 22, 2026 3 Min Read
67 0

Key Takeaways

  • A 23-year-old Canadian man has been arrested for allegedly operating the KimWolf DDoS botnet.
  • KimWolf weaponized over a million IoT devices, including those on the U.S. Department of Defense Information Network.
  • The botnet facilitated DDoS attacks peaking at nearly 30 Tbps, causing significant financial losses for victims.
  • The arrest is part of a broader international effort to disrupt major IoT DDoS-for-hire services.

Canadian and U.S. law enforcement agencies have apprehended an Ottawa resident in connection with the operation of “KimWolf,” a massive internet-of-things (IoT) distributed denial-of-service (DDoS) botnet. The 23-year-old suspect is accused of weaponizing more than a million internet-connected devices globally, including systems within Alaska and the critical U.S. Department of Defense Information Network (DoDIN).

Table Of Content

  • Key Takeaways
  • Global Takedown and Infrastructure Seizures
  • What You Should Do

An unsealed criminal complaint filed in the District of Alaska identifies the alleged perpetrator as Jacob Butler, also known by his online alias “Dort.” Butler faces accusations of developing and managing the KimWolf botnet as part of a DDoS-as-a-service operation, offering its substantial attack capabilities to other cybercriminals.

KimWolf reportedly compromised consumer and small-office devices, such as digital photo frames and webcams, which are typically protected by firewalls. These devices were covertly enrolled into a vast, globally distributed infrastructure used for launching high-volume DDoS campaigns against targets worldwide, including IP ranges associated with the DoDIN.

Investigators have linked KimWolf to DDoS attacks that reached peaks of nearly 30 Tbps. This places the botnet among the most significant volumetric events recorded to date, with some victims reporting financial losses exceeding one million dollars.

Global Takedown and Infrastructure Seizures

Butler’s arrest in Ottawa was executed under a U.S. extradition warrant, following a coordinated operation involving the U.S. Department of Justice, the Defense Criminal Investigative Service (DCIS), and Canadian law enforcement. He now faces one count of aiding and abetting computer intrusion in the United States, a charge that carries a maximum penalty of 10 years in prison upon conviction, with the final sentence to be determined under U.S. Sentencing Guidelines.

This arrest is a component of a larger court-authorized operation conducted in March 2026, which successfully disrupted several high-impact IoT DDoS botnets. This broader action targeted services including Aisuru, KimWolf, JackSkid, and Mossad, primarily through the seizure of their command-and-control (C2) infrastructure.

In a related enforcement action, the Central District of California unsealed seizure warrants against 45 DDoS-for-hire platforms alleged to support or collaborate with services like KimWolf. Authorities seized the associated domains and redirected them to a law enforcement “splash page,” which now serves to warn visitors about the illegal nature of DDoS attacks and boot/stressor services.

Court filings indicate that investigators established Butler’s connection to KimWolf’s administration through a comprehensive array of evidence. This included IP address data, online account records, payment and transaction trails, and logs from encrypted messaging platforms, all obtained through legal processes. This evidentiary mosaic reportedly links his online persona, “Dort,” directly to the botnet’s core operational infrastructure and its customer-facing DDoS-for-hire activities.

The success of this operation was heavily reliant on extensive public-private collaboration. Contributions from a wide spectrum of technology, hosting, security, and networking providers were crucial. Their telemetry, abuse handling, and infrastructure intelligence were instrumental in mapping KimWolf’s extensive ecosystem, identifying key C2 nodes, and facilitating the coordinated seizures and sinkholing actions.

Butler currently remains in custody in Canada as U.S. prosecutors, spearheaded by the U.S. Attorney’s Office for the District of Alaska and supported by DCIS and the FBI Anchorage Field Office, pursue his extradition and further legal proceedings in the ongoing KimWolf case.

What You Should Do

  • Regularly update firmware on all IoT devices (routers, cameras, smart home devices) to the latest versions.
  • Change default passwords on all IoT devices to strong, unique passwords.
  • Isolate IoT devices on a separate network segment or VLAN to limit their access to critical internal systems.
  • Monitor network traffic for unusual spikes or outbound connections from IoT devices, which could indicate compromise.
  • Implement DDoS protection services at the network edge to mitigate large-scale attacks.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackSecurity

Share Article

Sarah simpson

Sarah simpson

Sarah is a cybersecurity journalist specializing in threat intelligence and malware analysis. With over 8 years of experience covering APT groups, zero-day exploits, and advanced persistent threats, Sarah brings deep technical expertise to breaking cybersecurity news. Previously, she worked as a security researcher at leading threat intelligence firms, where she analyzed malware samples and tracked cybercriminal operations. Sarah holds a Master's degree in Computer Science with a focus on cybersecurity and is a regular contributor to major security conferences.

Previous Post

macOS Malware Hides in Nested Folders to Evade Detection

Next Post

Operation DragonWhistle Targets Changzhou University with Malicious LNK Files

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Critical Red Hat ACM Vulnerability Lets Attackers Gain Cluster-Admin Access
August 10, 2026
GitHub Expands Malware Detection to 8 Package Registries
August 10, 2026
Google Play Apps Use Stealth Loaders to Deliver Anatsa Banking Malware
August 10, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
Jennifer sherman
Jennifer sherman
Emy Elsamnoudy
Emy Elsamnoudy
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us