KIMWOLF BOTNET DISMANTLED: 23-YEAR-OLD ARRESTED IN OTTAWA IN GLOBAL DDoS-FOR-HIRE OPERATION

Canadian federal authorities have arrested a 23-year-old Ottawa man in connection with "Kimwolf," a Mirai-variant botnet that infected approximately 2 million IoT devices worldwide and was actively rented out for distributed denial-of-service attacks on demand.
The arrest, coordinated by the Royal Canadian Mounted Police Cybercrime Unit alongside international partners, marks a significant blow against DDoS-for-hire infrastructure — commonly known as booter or stresser services. The suspect remains unidentified pending formal charges, apprehended after a months-long investigation tracing the botnet's command-and-control servers across multiple jurisdictions.
Kimwolf followed the blueprint of the original Mirai malware, which gained notoriety in 2016 after crippling DNS provider Dyn and disrupting major portions of the internet. Like its predecessor, it targeted connected devices — routers, IP cameras, smart TVs, and NAS units — exploiting default credentials to silently enlist them into its botnet army.
What distinguished Kimwolf from earlier Mirai variants was its remarkable scale and geographic footprint. At peak operation, the botnet commanded roughly 2 million compromised nodes distributed across North America, Europe, Asia, and Latin America — an enormous bandwidth pool available for weaponization against virtually any online target.
The operator monetized Kimwolf through a subscription model. Customers accessed an encrypted web panel to select targets, attack durations, and traffic vectors — UDP floods, HTTP floods, SYN floods — across tiered pricing plans. Clients ranged from gaming rivals seeking competitive edges to extortionists targeting businesses and financial platforms.
Authorities declined to reveal investigative methods, citing ongoing judicial proceedings. Researchers noted that operational security failures — reused cryptocurrency addresses and forum handles tied to earlier criminal personas — likely proved critical in unmasking the operator.
Charges reportedly include unauthorized access to computer systems, facilitating DDoS attacks for hire, and operating a criminal organization for profit. If convicted under Canadian cybercrime statutes, the suspect faces up to ten years imprisonment.
The Kimwolf case underscores the enduring threat of Mirai-derived botnets, a decade after the original source code leaked publicly in 2016. Security experts continue urging IoT manufacturers to enforce unique factory credentials and prioritize firmware updates — changes that would dramatically reduce the attack surface exploited by operations like Kimwolf. Coordinated takedowns targeting DDoS-for-hire infrastructure are expected to intensify across Five Eyes nations throughout 2026.