Kimwolf Taken Down: Canadian Operator Behind One of the World's Most Destructive DDoS-for-Hire Botnets Arrested
Jacob Butler, 23, faces U.S. federal charges after allegedly renting out a million-device botnet that targeted everything from private businesses to the Department of Defense.
Written by OutOfToken AI
May 24, 2026 · 4 min read · Synthesized from reporting by The Hacker News · How this works
U.S. and Canadian authorities have arrested Jacob Butler, a 23-year-old Ottawa resident accused of developing and operating Kimwolf — a DDoS-for-hire botnet that compromised more than one million devices worldwide and struck targets including the U.S. Department of Defense. The Department of Justice unsealed charges Thursday, revealing Butler was taken into custody in Ottawa under a U.S. extradition warrant. The arrest is the latest salvo in a coordinated international crackdown on the infrastructure that powers the cybercrime-as-a-service economy.
A Botnet Built for Hire
Kimwolf operated as a classic booter-stresser service — a platform that monetizes a network of hijacked machines by renting their combined bandwidth to paying customers who want to knock targets offline. Court documents describe Kimwolf as a variant of AISURU, a sophisticated botnet strain that has circulated in underground markets and is known for its aggressive propagation capabilities and resilience against takedown efforts. Butler, operating under the alias 'Dort,' allegedly built Kimwolf into one of the most potent DDoS platforms in circulation, offering tiered attack packages to clients through online storefronts designed to obscure the criminal nature of the service.
Scale, Targets, and Technical Reach
The scale of Kimwolf's infection footprint sets it apart from typical booter operations. With over one million compromised devices recruited into the botnet, Butler allegedly commanded enough aggregate bandwidth to sustain volumetric attacks capable of overwhelming even hardened infrastructure. Among the confirmed targets was the U.S. Department of Defense — a detail that almost certainly elevated federal interest and accelerated the extradition push. The botnet's AISURU lineage is technically significant: AISURU variants are designed to persist across reboots, resist standard remediation, and exploit a wide array of consumer router and IoT device vulnerabilities, giving operators a self-replenishing pool of attack nodes.
"Kimwolf infected more than one million devices globally — and counted the U.S. Department of Defense among its confirmed attack targets."
Cross-Border Enforcement and the Extradition Mechanism
Butler's arrest follows a broader law enforcement operation that dismantled several botnets in the months prior, signaling sustained pressure on the DDoS-for-hire ecosystem from agencies including the FBI and their Canadian counterparts. The use of an extradition warrant rather than a domestic Canadian charge underscores the degree to which U.S. prosecutors are willing to pursue foreign nationals who target American systems. If extradited and convicted, Butler faces a substantial federal sentence — DDoS conspiracy charges under the Computer Fraud and Abuse Act carry penalties that can stack significantly when attacks involve government infrastructure. Legal proceedings are expected to hinge on attribution evidence tying the 'Dort' alias to Butler's real-world identity and the Kimwolf command-and-control infrastructure.
Butler's arrest reinforces a pattern: law enforcement agencies have shifted from reactive takedowns to proactive, intelligence-driven prosecution of botnet operators regardless of jurisdiction. The Kimwolf case demonstrates that running a DDoS-for-hire service — even from outside U.S. borders — now carries genuine extradition risk. As IoT device proliferation continues to hand botnet operators an ever-expanding attack surface, the pressure on international legal frameworks to close jurisdictional gaps will only intensify. For would-be operators in the underground market, the message is unambiguous: the alias offers no real cover.
Editorial Note
The Hacker News is a reputable cybersecurity news source with generally reliable reporting on law enforcement actions and cybercriminal arrests. DoJ announcements regarding botnet operators are typically verified through official channels and press releases. The specific technical details about Kimwolf being a variant of AISURU and the attribution to a 23-year-old Canadian named Jacob Butler (aka Dort) would be verifiable through official DoJ statements, though this summary appears truncated.
Claim Tracker
AI-assessed
DoJ announcement confirmed this arrest on the stated date
Based on allegations in court documents; not independently confirmed in excerpt
Alleged targeting mentioned but no specific incidents detailed or confirmed
Court documents state this assessment but technical verification not provided in article
Confirmed in DoJ charging documents referenced in article
Ask AI about this story
// discussion
sign in to join the discussion