BOTNET TAKEDOWN: The Fall of Kimwolf — A DDoS-for-Hire Empire Built on 2 Million Compromised Devices

On May 20, 2026, U.S. and Canadian authorities announced the arrest of Jacob Butler, a 23-year-old Ottawa resident known online as "Dort," suspected of building and operating Kimwolf — one of the most destructive IoT botnets ever documented.
What Was Kimwolf?
Kimwolf was a Mirai-class botnet: malware engineered to silently compromise internet-connected devices — home routers, IP cameras, smart appliances — and enlist them in massive Distributed Denial-of-Service (DDoS) attacks. At its peak, Kimwolf had enslaved nearly 2 million devices worldwide, including systems located in Alaska, which established federal jurisdiction in the United States.
Its business model was straightforward and alarming: a DDoS-for-hire service. Paying customers could direct the botnet's full firepower at any target of their choosing, with little to no technical expertise required. Attacks peaked at nearly 30 terabits per second — a documented record in DDoS attack volume, and a scale capable of bringing down most enterprise-grade network defenses.
The Arrest
Butler was formally charged on April 10, 2026. The U.S. charges were filed in the District of Alaska, where several compromised devices were located. Canadian authorities apprehended him on May 20, following a cross-border investigation supported by IP logs, account records, and transaction data.
He faces charges in both jurisdictions — including unauthorized computer access, criminal mischief, and federal aiding of computer intrusion in the U.S. If convicted, Butler faces up to 10 years in federal prison.
Infrastructure Dismantled
The arrest was part of a larger international operation. On March 19, 2026, U.S. authorities — working with global partners — had already seized the technical infrastructure of Kimwolf alongside three competing botnets: Aisuru, JackSkid, and Mossad. All four were racing to compromise the same pool of unpatched IoT devices.
The Bigger Picture: IoT Security Is Still Broken
Kimwolf is not an outlier — it is a symptom. IoT security remains critically underdeveloped. Millions of devices still ship with default credentials, outdated firmware, and no automatic update mechanism. Mirai-class botnets have exploited this structural weakness since 2016, and the threat continues to grow in scale and sophistication.
For network engineers and security professionals, the message is urgent: edge device hardening is non-negotiable. Change default credentials. Segment IoT traffic on dedicated VLANs. Monitor for abnormal outbound traffic patterns. Treat firmware patching as active threat prevention — not routine maintenance.
Botnets like Kimwolf are not built overnight. They grow quietly — one unpatched device at a time.