Law enforcement in Canada has apprehended a 23-year-old man from Ottawa in connection with the development and operation of Kimwolf, a rapidly propagating Internet-of-Things botnet that compromised millions of connected devices. The botnet was leveraged to launch a series of massive distributed denial-of-service attacks throughout the preceding half-year. The suspect now faces criminal charges in both Canadian and U.S. jurisdictions.
An unsealed criminal complaint filed in an Alaska district court identifies Jacob Butler, known online as "Dort," as the operator behind the Kimwolf DDoS botnet. According to a Department of Justice statement, Butler's arrest by the Ontario Provincial Police followed the issuance of a U.S. extradition warrant. He remains in Canadian custody pending an initial hearing scheduled for the following week.
Authorities determined that Kimwolf targeted connected devices typically isolated from broader internet connectivity, including digital photo frames and webcams. Once infected, these systems were either leased to other criminal actors or conscripted into large-scale DDoS operations, including attacks directed at Department of Defense internet address ranges. The Defense Criminal Investigative Service and the FBI's Anchorage field office are jointly investigating the matter.
According to the Justice Department, "KimWolf was tied to DDoS attacks which were measured at nearly 30 Terabits per second, a record in recorded DDoS attack volume. These attacks resulted in financial losses which, for some victims, exceeded one million dollars. The KimWolf botnet is alleged to have issued over 25,000 attack commands."
On March 19, U.S. law enforcement coordinated with international partners to dismantle the infrastructure supporting Kimwolf alongside three competing botnets designated Aisuru, JackSkid, and Mossad, all of which targeted the same vulnerable device population.
KrebsOnSecurity publicly identified Butler as the Kimwolf operator on February 28 after analyzing his email accounts, forum registrations, and communications across Telegram and Discord. Following the exposure of his identity, Dort escalated his harassment campaign against researchers instrumental in tracking him and disrupting botnet expansion.
Butler claimed responsibility for at least two swatting incidents targeting the founder of Synthient, a security firm that identified and helped remediate a critical vulnerability that Kimwolf exploited for rapid propagation. The Justice Department acknowledged Synthient's contributions, and company founder Ben Brundage expressed his reaction to Butler's detention: "Hopefully this will end the harassment."
Investigators established Butler's connection to Kimwolf administration through IP addresses, account credentials, financial transaction records, and digital communications obtained via legal process. The complaint demonstrates that Butler maintained minimal separation between his personal and criminal identities.
In April, the Justice Department coordinated with European authorities to seize domain names associated with approximately four dozen DDoS-for-hire operations. The DOJ confirmed that at least one of these services had collaborated with Butler's botnet infrastructure.
A search warrant executed on March 19 at Butler's Ottawa residence by the Ontario Provincial Police resulted in the seizure of multiple computing devices. Butler now faces three Canadian charges: unauthorized computer use, possession of a device intended for unauthorized system access or computer mischief, and computer data mischief. He is scheduled to remain detained until a May 26 hearing.
In U.S. federal court, Butler faces one count of aiding and abetting computer intrusion. Should he be extradited, convicted, and sentenced in the United States, he could receive up to 10 years imprisonment, though the U.S. Sentencing Guidelines would likely reduce this maximum based on mitigating factors including his age, absence of prior criminal convictions, and potential cooperation with authorities.
Source: Krebs on Security