U.S. and Canadian authorities arrested 23-year-old Ottawa resident Jacob Butler, also known as "Dort," and unsealed charges alleging he was a principal administrator of the Kimwolf DDoS botnet. Prosecutors said Kimwolf was a variant of the Aisuru botnet and part of a broader ecosystem that hijacked millions of internet-connected devices, including more than 2 million Android TV devices and other IoT hardware such as webcams and digital photo frames. Investigators said the botnet enabled hundreds of thousands of attacks, issued more than 25,000 attack commands, and was linked to DDoS activity reaching nearly 30 Tbps, including attacks affecting Department of Defense network IP ranges.
Authorities said Butler was identified through overlapping IP usage, Google account artifacts, machine cookies, Discord and messaging records, transaction data, and other account information. Canadian officials arrested him on a U.S. extradition warrant while also filing domestic computer crime charges, and the Justice Department said law enforcement had already seized infrastructure tied to Kimwolf, Aisuru, JackSkid, and Mossad in March. Court records and reporting indicate Kimwolf resumed operations after that takedown, and the case also includes allegations that Butler harassed security researchers and claimed responsibility for swatting attacks against Synthient founder Ben Brundage after the company helped mitigate a flaw that Kimwolf had exploited for rapid spread.

Pull IOCs and campaign context straight into your stack.
6 events from the most recent confirmed update back to the earliest known activity.
U.S. prosecutors unsealed a criminal complaint charging Butler with serving as a principal administrator of Kimwolf, described as a variant of the Aisuru botnet. The Justice Department said the broader botnet ecosystem hijacked millions of devices and enabled hundreds of thousands of DDoS attacks, including attacks affecting Department of Defense IP ranges.
Canadian authorities arrested 23-year-old Jacob Butler, known as “Dort,” in Canada for allegedly building and administering the Kimwolf botnet. The arrest was made under a U.S. extradition warrant, and Canadian authorities also filed domestic computer crime charges.
Court records cited in reporting indicate Kimwolf resumed operations despite the March infrastructure seizure. This showed the botnet remained active after the initial law enforcement disruption.
Law enforcement seized infrastructure tied to Kimwolf on March 19, alongside the Aisuru, JackSkid, and Mossad botnets. Officials also linked at least one seized DDoS-for-hire service to Butler’s operation.
Prior reporting by KrebsOnSecurity identified Ottawa resident Jacob Butler, also known as “Dort,” in connection with the Kimwolf botnet. The article states this identification occurred in February 2026.
Qianxin XLab published a report on the Kimwolf botnet, describing it as a massive operation that had infected 1.8 million Android devices worldwide. The report represents an early public technical disclosure of the botnet before the later 2026 attribution and law enforcement actions.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
11 references tracked. Mallory keeps watching after this page renders.
xakep.ru
Open sourcecybersecuritynews.com
Open sourcesecurityaffairs.com
Open sourcethehackernews.com
Open sourcecyberscoop.com
Open sourcekrebsonsecurity.com
Open sourcebsi.bund.de
Open sourcelinkedin.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.