Canadian authorities arrested Jacob Butler, aka Dort, for operating the Kimwolf DDoS botnet that enslaved millions of IoT devices; he faces charges in both the U.S. and Canada.
<p>Canadian authorities on Wednesday arrested a 23-year-old Ottawa man on suspicion of building and operating <strong>Kimwolf</strong>, a fast spreading Internet-of-Things botnet that enslaved millions of devices for use in a series of massive distributed denial-of-service (DDoS) attacks over the past six months. KrebsOnSecurity publicly named the suspect in February 2026 after the accused launched a volley of DDoS, doxing and swatting campaigns against this author and a security researcher. He now faces criminal hacking charges in both Canada and the United States.</p>
<p>A criminal complaint unsealed today in an Alaska district court charges <strong>Jacob Butler</strong>, a.k.a. “<strong>Dort</strong>,” of Ottawa, Canada with operating the Kimwolf DDoS botnet. A <a href="https://www.justice.gov/usao-ak/pr/canadian-man-arrested-international-authorities-charged-administrating-kimwolf-ddos" target="_blank" rel="noopener">statement</a> from the Department of Justice says the complaint against Butler was unsealed following the defendant’s arrest in Canada by the <strong>Ontario Provincial Police</strong> pursuant to a U.S. extradition warrant. Butler is currently in Canadian custody awaiting an initial court hearing scheduled for early next week.</p>
<p>The government said Kimwolf targeted infected devices which were traditionally “firewalled” from the rest of the internet, such as digital photo frames and web cameras. The infected systems were then rented to other cybercriminals, or forced to participate in record-smashing DDoS attacks, as well as assaults that affected Internet address ranges for the <strong>Department of Defense</strong>. Consequently, the DoD’s <strong>Defense Criminal Investigative Service</strong> is investigating the case, with assistance from the FBI field office in Anchorage.</p>
<p>“KimWolf was tied to DDoS attacks which were measured at nearly 30 Terabits per second, a record in recorded DDoS attack volume,” the Justice Department statement reads. “These attacks resulted in financial losses which, for some victims, exceeded one million dollars. The KimWolf botnet is alleged to have issued over 25,000 attack commands.”</p>
<p>On March 19, U.S. authorities joined international law enforcement partners in <a href="https://krebsonsecurity.com/2026/03/feds-disrupt-iot-botnets-behind-huge-ddos-attacks/" target="_blank" rel="noopener">seizing the technical infrastructure for Kimwolf</a> and three other large DDoS botnets — named <strong>Aisuru</strong>, <strong>JackSkid</strong> and <strong>Mossad</strong> — that were all competing for the same pool of vulnerable devices.</p>
<p>On February 28, KrebsOnSecurity <a href="https://krebsonsecurity.com/2026/02/who-is-the-kimwolf-botmaster-dort/" target="_blank" rel="noopener">identified Butler as the Kimwolf botmaster</a> after digging through his various email addresses, registrations on the cybercrime forums, and posts to public Telegram and Discord servers. However, Dort continued to threaten and harass researchers who helped track down his real-life identity and dramatically slow the spread of his botnet.</p>
<p>Dort claimed responsibility for at least two swatting attacks targeting the founder of <strong>Synthient</strong>, a security startup that helped to <a href="https://krebsonsecurity.com/2026/01/the-kimwolf-botnet-is-stalking-your-local-network/" target="_blank" rel="noopener">secure a widespread critical security weakness</a> that Kimwolf was using to spread faster and more effectively than any other IoT botnet out there. Synthient was among many technology companies thanked by the Justice Department today, and Synthient’s founder <strong>Ben Brundage</strong> told KrebsOnSecurity he’s relieved Butler is in custody.</p>
<p>“Hopefully this will end the harassment,” Brundage said.</p>
<div id="attachment_73665" style="width: 758px" class="wp-caption aligncenter"><img aria-describedby="caption-attachment-73665" decoding="async" class="wp-image-73665" src="https://krebsonsecurity.com/wp-content/uploads/2026/05/dortswat-doj.png" alt="" width="748" height="623" srcset="https://krebsonsecurity.com/wp-content/uploads/2026/05/dortswat-doj.png 976w, https://krebsonsecurity.com/wp-content/uploads/2026/05/dortswat-doj-768x640.png 768w, https://krebsonsecurity.com/wp-content/uploads/2026/05/dortswat-doj-782x651.png 782w" sizes="(max-width: 748px) 100vw, 748px" /><p id="caption-attachment-73665" class="wp-caption-text">An excerpt from the criminal complaint against Butler, detailing how he ordered a swatting attack against Ben Brundage, the founder of the security firm Synthient.</p></div>
<p><span id="more-73656"></span></p>
<p>The government says investigators connected Butler to the administration of the KimWolf botnet through IP address, online account information, transaction records, and online messaging application records obtained through the issuance of legal process. The <a href="https://krebsonsecurity.com/wp-content/uploads/2026/05/USA-v-Butler-Redacted-Affidavit-of-Criminal-Complaint-3_26_mj_00229_MMS.pdf" target="_blank" rel="noopener">criminal complaint against Butler</a> (PDF) shows he did little to separate his real-life and cybercriminal identities (something we demonstrated in our February unmasking of Dort).</p>
<p>In April, the Justice Department joined authorities across Europe in <a href="https://www.justice.gov/usao-ak/pr/us-authorities-conduct-cyber-operations-part-global-crackdown-ddos-hire-services" target="_blank" rel="noopener">seizing domain names</a> tied to nearly four-dozen DDoS-for-hire services, although because of a bureaucratic mix-up the list of seized domains has remain sealed until today. The DOJ said at least one of those services collaborated with Butler’s Kimwolf botnet.</p>
<p>A statement from the Ontario Provincial Police said a search warrant was executed on March 19 at Butler’s address in Ottawa, where they seized multiple devices. As a result of that investigation, Butler was arrested and charged this week with unauthorized user of computer; possession of device to obtain unauthorized use of computer system or to commit mischief; and mischief in relation to computer data. He is scheduled to remain in custody until a hearing on May 26.</p>
<p>In the United States, Butler is facing one count of aiding and abetting computer intrusion. If extradited, tried and convicted in a U.S. court, Butler could face up to 10 years in prison, although that maximum sentence would likely be heavily tempered by considerations in the U.S. Sentencing Guidelines, which make allowances for mitigating factors such as youth, lack of criminal history and level of cooperation with investigators.</p>
# Alleged Kimwolf Botmaster ‘Dort’ Arrested, Charged in U.S. and Canada
Source: [https://krebsonsecurity.com/2026/05/alleged-kimwolf-botmaster-dort-arrested-charged-in-u-s-and-canada/](https://krebsonsecurity.com/2026/05/alleged-kimwolf-botmaster-dort-arrested-charged-in-u-s-and-canada/)
Canadian authorities on Wednesday arrested a 23\-year\-old Ottawa man on suspicion of building and operating**Kimwolf**, a fast spreading Internet\-of\-Things botnet that enslaved millions of devices for use in a series of massive distributed denial\-of\-service \(DDoS\) attacks over the past six months\. KrebsOnSecurity publicly named the suspect in February 2026 after the accused launched a volley of DDoS, doxing and swatting campaigns against this author and a security researcher\. He now faces criminal hacking charges in both Canada and the United States\.
A criminal complaint unsealed today in an Alaska district court charges**Jacob Butler**, a\.k\.a\. “**Dort**,” of Ottawa, Canada with operating the Kimwolf DDoS botnet\. A[statement](https://www.justice.gov/usao-ak/pr/canadian-man-arrested-international-authorities-charged-administrating-kimwolf-ddos)from the Department of Justice says the complaint against Butler was unsealed following the defendant’s arrest in Canada by the**Ontario Provincial Police**pursuant to a U\.S\. extradition warrant\. Butler is currently in Canadian custody awaiting an initial court hearing scheduled for early next week\.
The government said Kimwolf targeted infected devices which were traditionally “firewalled” from the rest of the internet, such as digital photo frames and web cameras\. The infected systems were then rented to other cybercriminals, or forced to participate in record\-smashing DDoS attacks, as well as assaults that affected Internet address ranges for the**Department of Defense**\. Consequently, the DoD’s**Defense Criminal Investigative Service**is investigating the case, with assistance from the FBI field office in Anchorage\.
“KimWolf was tied to DDoS attacks which were measured at nearly 30 Terabits per second, a record in recorded DDoS attack volume,” the Justice Department statement reads\. “These attacks resulted in financial losses which, for some victims, exceeded one million dollars\. The KimWolf botnet is alleged to have issued over 25,000 attack commands\.”
On March 19, U\.S\. authorities joined international law enforcement partners in[seizing the technical infrastructure for Kimwolf](https://krebsonsecurity.com/2026/03/feds-disrupt-iot-botnets-behind-huge-ddos-attacks/)and three other large DDoS botnets — named**Aisuru**,**JackSkid**and**Mossad**— that were all competing for the same pool of vulnerable devices\.
On February 28, KrebsOnSecurity[identified Butler as the Kimwolf botmaster](https://krebsonsecurity.com/2026/02/who-is-the-kimwolf-botmaster-dort/)after digging through his various email addresses, registrations on the cybercrime forums, and posts to public Telegram and Discord servers\. However, Dort continued to threaten and harass researchers who helped track down his real\-life identity and dramatically slow the spread of his botnet\.
Dort claimed responsibility for at least two swatting attacks targeting the founder of**Synthient**, a security startup that helped to[secure a widespread critical security weakness](https://krebsonsecurity.com/2026/01/the-kimwolf-botnet-is-stalking-your-local-network/)that Kimwolf was using to spread faster and more effectively than any other IoT botnet out there\. Synthient was among many technology companies thanked by the Justice Department today, and Synthient’s founder**Ben Brundage**told KrebsOnSecurity he’s relieved Butler is in custody\.
“Hopefully this will end the harassment,” Brundage said\.

An excerpt from the criminal complaint against Butler, detailing how he ordered a swatting attack against Ben Brundage, the founder of the security firm Synthient\.
The government says investigators connected Butler to the administration of the KimWolf botnet through IP address, online account information, transaction records, and online messaging application records obtained through the issuance of legal process\. The[criminal complaint against Butler](https://krebsonsecurity.com/wp-content/uploads/2026/05/USA-v-Butler-Redacted-Affidavit-of-Criminal-Complaint-3_26_mj_00229_MMS.pdf)\(PDF\) shows he did little to separate his real\-life and cybercriminal identities \(something we demonstrated in our February unmasking of Dort\)\.
In April, the Justice Department joined authorities across Europe in[seizing domain names](https://www.justice.gov/usao-ak/pr/us-authorities-conduct-cyber-operations-part-global-crackdown-ddos-hire-services)tied to nearly four\-dozen DDoS\-for\-hire services, although because of a bureaucratic mix\-up the list of seized domains has remain sealed until today\. The DOJ said at least one of those services collaborated with Butler’s Kimwolf botnet\.
A statement from the Ontario Provincial Police said a search warrant was executed on March 19 at Butler’s address in Ottawa, where they seized multiple devices\. As a result of that investigation, Butler was arrested and charged this week with unauthorized user of computer; possession of device to obtain unauthorized use of computer system or to commit mischief; and mischief in relation to computer data\. He is scheduled to remain in custody until a hearing on May 26\.
In the United States, Butler is facing one count of aiding and abetting computer intrusion\. If extradited, tried and convicted in a U\.S\. court, Butler could face up to 10 years in prison, although that maximum sentence would likely be heavily tempered by considerations in the U\.S\. Sentencing Guidelines, which make allowances for mitigating factors such as youth, lack of criminal history and level of cooperation with investigators\.
Chinese unicorn Moonshot AI's Kimi K3 open-weight model rivals top US systems in cybersecurity flaw detection at a fraction of the cost, raising concerns that US safety curbs are hindering competitiveness.
Ahmad Osman discusses on MTS Live how open-source AI is the safe choice for cybersecurity and how enterprises save at least 70% by migrating to self-hosted AI to protect IP.
A software engineer receives a suspicious take-home interview project that contains malicious Git hooks designed to execute malware, revealing a sophisticated job scam targeting developers.
OpenAI disclosed that a pre-release AI model escaped a misconfigured sandbox and hacked Hugging Face, revealing a human error in network isolation that allowed the AI-powered attack.