Canadian Man Arrested for Operating KimWolf DDoS Botnet
Key Takeaways A 23-year-old Canadian man has been arrested for allegedly operating the KimWolf DDoS botnet. KimWolf weaponized over a million IoT devices, including those on the U.S. Department of...
Key Takeaways
- A 23-year-old Canadian man has been arrested for allegedly operating the KimWolf DDoS botnet.
- KimWolf weaponized over a million IoT devices, including those on the U.S. Department of Defense Information Network.
- The botnet facilitated DDoS attacks peaking at nearly 30 Tbps, causing significant financial losses for victims.
- The arrest is part of a broader international effort to disrupt major IoT DDoS-for-hire services.
Canadian and U.S. law enforcement agencies have apprehended an Ottawa resident in connection with the operation of “KimWolf,” a massive internet-of-things (IoT) distributed denial-of-service (DDoS) botnet. The 23-year-old suspect is accused of weaponizing more than a million internet-connected devices globally, including systems within Alaska and the critical U.S. Department of Defense Information Network (DoDIN).
Table Of Content
An unsealed criminal complaint filed in the District of Alaska identifies the alleged perpetrator as Jacob Butler, also known by his online alias “Dort.” Butler faces accusations of developing and managing the KimWolf botnet as part of a DDoS-as-a-service operation, offering its substantial attack capabilities to other cybercriminals.
KimWolf reportedly compromised consumer and small-office devices, such as digital photo frames and webcams, which are typically protected by firewalls. These devices were covertly enrolled into a vast, globally distributed infrastructure used for launching high-volume DDoS campaigns against targets worldwide, including IP ranges associated with the DoDIN.
Investigators have linked KimWolf to DDoS attacks that reached peaks of nearly 30 Tbps. This places the botnet among the most significant volumetric events recorded to date, with some victims reporting financial losses exceeding one million dollars.
Global Takedown and Infrastructure Seizures
Butler’s arrest in Ottawa was executed under a U.S. extradition warrant, following a coordinated operation involving the U.S. Department of Justice, the Defense Criminal Investigative Service (DCIS), and Canadian law enforcement. He now faces one count of aiding and abetting computer intrusion in the United States, a charge that carries a maximum penalty of 10 years in prison upon conviction, with the final sentence to be determined under U.S. Sentencing Guidelines.
This arrest is a component of a larger court-authorized operation conducted in March 2026, which successfully disrupted several high-impact IoT DDoS botnets. This broader action targeted services including Aisuru, KimWolf, JackSkid, and Mossad, primarily through the seizure of their command-and-control (C2) infrastructure.
In a related enforcement action, the Central District of California unsealed seizure warrants against 45 DDoS-for-hire platforms alleged to support or collaborate with services like KimWolf. Authorities seized the associated domains and redirected them to a law enforcement “splash page,” which now serves to warn visitors about the illegal nature of DDoS attacks and boot/stressor services.
Court filings indicate that investigators established Butler’s connection to KimWolf’s administration through a comprehensive array of evidence. This included IP address data, online account records, payment and transaction trails, and logs from encrypted messaging platforms, all obtained through legal processes. This evidentiary mosaic reportedly links his online persona, “Dort,” directly to the botnet’s core operational infrastructure and its customer-facing DDoS-for-hire activities.
The success of this operation was heavily reliant on extensive public-private collaboration. Contributions from a wide spectrum of technology, hosting, security, and networking providers were crucial. Their telemetry, abuse handling, and infrastructure intelligence were instrumental in mapping KimWolf’s extensive ecosystem, identifying key C2 nodes, and facilitating the coordinated seizures and sinkholing actions.
Butler currently remains in custody in Canada as U.S. prosecutors, spearheaded by the U.S. Attorney’s Office for the District of Alaska and supported by DCIS and the FBI Anchorage Field Office, pursue his extradition and further legal proceedings in the ongoing KimWolf case.
What You Should Do
- Regularly update firmware on all IoT devices (routers, cameras, smart home devices) to the latest versions.
- Change default passwords on all IoT devices to strong, unique passwords.
- Isolate IoT devices on a separate network segment or VLAN to limit their access to critical internal systems.
- Monitor network traffic for unusual spikes or outbound connections from IoT devices, which could indicate compromise.
- Implement DDoS protection services at the network edge to mitigate large-scale attacks.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.