Alleged Kimwolf Botmaster 'Dort' Charged Following Global Botnet
Jacob Butler, 23, faces hacking charges in the U.S. and Canada for allegedly operating an IoT botnet that launched record-shattering DDoS attacks.
Security reporter
Reports on cybersecurity incidents, threat actors, and digital policy with a focus on technical claims, vendor disclosures, and security-response timelines.
Editorial responsibility: Lead reviewer for threat attribution, incident framing, and security vendor claims
Primary source: Krebs on Security. Full source links and update notes are below.
Fast summary
Start here
- Jacob Butler (alias 'Dort') was arrested by Ontario Provincial Police on a U.S. extradition warrant related to the Kimwolf botnet.
- The Kimwolf botnet utilized millions of IoT devices to launch DDoS attacks reaching a record 30 terabits per second.
- Butler is accused of targeting Department of Defense infrastructure and orchestrating swatting attacks against security researchers.

What happened
Canadian authorities have arrested 23-year-old Jacob Butler, also known online as "Dort," over allegations that he operated the Kimwolf botnet, a massive network of hijacked internet-connected devices used to launch some of the largest distributed denial-of-service attacks on record. The arrest followed a joint U.S.-Canada effort and was tied to an American extradition request, showing how seriously both countries are treating the case.
Kimwolf matters because it represents a particularly dangerous form of criminal infrastructure: a botnet built from vulnerable internet-of-things devices that can be weaponized at enormous scale. According to the allegations, the network generated attacks approaching 30 terabits per second, a volume large enough to overwhelm major targets and to raise broader concerns about how exposed the IoT ecosystem remains.
What's new in this update
The unsealed U.S. complaint has given a clearer picture of both the scale of the network and the case against Butler. Investigators say they linked him to Kimwolf through IP evidence, financial records, and messaging logs. They also say the botnet was not used only for one-off stunts or isolated disruption. It allegedly functioned as part of a broader cybercrime economy that included DDoS-for-hire services and coordinated intimidation campaigns.
Authorities also allege that Butler targeted researchers who investigated him, using swatting and doxing tactics against at least some of the people tracking the botnet. That detail matters because it shows the case is not only about technical disruption. It is also about the use of harassment and coercion to shield criminal infrastructure from scrutiny.
Key details
Kimwolf reportedly infected millions of IoT devices, including internet-connected cameras, digital frames, and similar products that often ship with weak security and poor patching support. That is a familiar botnet pattern, but the alleged scale of Kimwolf makes the case especially notable. IoT devices are attractive to botnet operators because they are numerous, always online, and frequently ignored by users after installation.
The core allegations include:
- Launching DDoS attacks against major targets, including Defense Department ranges.
- Renting or coordinating access with booter and stresser services.
- Issuing tens of thousands of attack commands.
- Harassing researchers who publicly attributed the botnet.
The network was reportedly disrupted in March along with related botnet infrastructure, but the arrest is important because takedowns without accountable operators often produce only temporary relief.
Background and context
The Kimwolf case sits inside a much longer story about the insecurity of consumer and commercial IoT devices. For years, law enforcement and researchers have warned that cheap, poorly maintained internet-connected hardware can be turned into attack infrastructure at industrial scale. Botnet operators do not need cutting-edge zero-days if enough devices are exposed with default credentials, outdated firmware, or weak management interfaces.
The cross-border nature of the case also matters. Cybercrime investigations frequently stall when infrastructure, victims, suspects, and investigators are spread across jurisdictions. The Butler arrest suggests that coordinated law enforcement can still produce meaningful results when technical investigation, attribution, and extradition requests align.
What to watch next
The next stage will be the extradition process and whatever additional evidence emerges in court filings. Investigators may also continue pursuing associated DDoS-for-hire actors and customers connected to Kimwolf. The broader strategic question is whether cases like this deter future operators or whether the underlying IoT insecurity remains so widespread that new botnets will simply replace the old ones.
Why this matters
This matters because botnets like Kimwolf are not fringe nuisances. They are industrial-scale attack platforms built on everyday insecure devices. Arresting an alleged operator is a meaningful win, but the case also highlights how much critical internet stability still depends on fixing a deeply insecure hardware ecosystem.
Reader context
This story belongs to Northstar Herald's Cybersecurity and National Security coverage, with related entities including Kimwolf, Botnet, DDoS, Jacob Butler. The report is based on Krebs on Security source material.
Related coverage
Why it matters
The arrest marks a major strike against high-volume DDoS infrastructure and demonstrates the efficacy of international cooperation in dismantling criminal IoT botnets.
Read next
Follow this story through the topic hub, more security coverage, and the latest updates.
Weekly briefing
Get the week's key developments in one concise email.
Get a fast catch-up on the biggest stories, the context behind them, and the links worth your time.
Cadence
Weekly, for a quick catch-up
Coverage
AI, business, world, security, sports
Format
Clear takeaways and useful context
Request the briefing
Leave your email to open a prepared request and get on the list for the weekly briefing.
About the byline
Security reporter
Marcus Kane covers cybersecurity, national-security technology, and digital risk, tracking how breaches, state-backed operations, and platform vulnerabilities affect institutions and users.
Sources and methodology