Kimwolf Taken Down: Canadian Operator Behind One of the World's Most Destructive DDoS-for-Hire Botnets Arrested

Kimwolf Taken Down: Canadian Operator Behind One of the World's Most Destructive DDoS-for-Hire Botnets Arrested

Jacob Butler, 23, faces U.S. federal charges after allegedly renting out a million-device botnet that targeted everything from private businesses to the Department of Defense.

Written by OutOfToken AI

May 24, 2026 · 4 min read · Synthesized from reporting by The Hacker News · How this works

AI Likely Accurate · 7/10

U.S. and Canadian authorities have arrested Jacob Butler, a 23-year-old Ottawa resident accused of developing and operating Kimwolf — a DDoS-for-hire botnet that compromised more than one million devices worldwide and struck targets including the U.S. Department of Defense. The Department of Justice unsealed charges Thursday, revealing Butler was taken into custody in Ottawa under a U.S. extradition warrant. The arrest is the latest salvo in a coordinated international crackdown on the infrastructure that powers the cybercrime-as-a-service economy.

A Botnet Built for Hire

Kimwolf operated as a classic booter-stresser service — a platform that monetizes a network of hijacked machines by renting their combined bandwidth to paying customers who want to knock targets offline. Court documents describe Kimwolf as a variant of AISURU, a sophisticated botnet strain that has circulated in underground markets and is known for its aggressive propagation capabilities and resilience against takedown efforts. Butler, operating under the alias 'Dort,' allegedly built Kimwolf into one of the most potent DDoS platforms in circulation, offering tiered attack packages to clients through online storefronts designed to obscure the criminal nature of the service.

Scale, Targets, and Technical Reach

The scale of Kimwolf's infection footprint sets it apart from typical booter operations. With over one million compromised devices recruited into the botnet, Butler allegedly commanded enough aggregate bandwidth to sustain volumetric attacks capable of overwhelming even hardened infrastructure. Among the confirmed targets was the U.S. Department of Defense — a detail that almost certainly elevated federal interest and accelerated the extradition push. The botnet's AISURU lineage is technically significant: AISURU variants are designed to persist across reboots, resist standard remediation, and exploit a wide array of consumer router and IoT device vulnerabilities, giving operators a self-replenishing pool of attack nodes.

"Kimwolf infected more than one million devices globally — and counted the U.S. Department of Defense among its confirmed attack targets."

Cross-Border Enforcement and the Extradition Mechanism

Butler's arrest follows a broader law enforcement operation that dismantled several botnets in the months prior, signaling sustained pressure on the DDoS-for-hire ecosystem from agencies including the FBI and their Canadian counterparts. The use of an extradition warrant rather than a domestic Canadian charge underscores the degree to which U.S. prosecutors are willing to pursue foreign nationals who target American systems. If extradited and convicted, Butler faces a substantial federal sentence — DDoS conspiracy charges under the Computer Fraud and Abuse Act carry penalties that can stack significantly when attacks involve government infrastructure. Legal proceedings are expected to hinge on attribution evidence tying the 'Dort' alias to Butler's real-world identity and the Kimwolf command-and-control infrastructure.

Butler's arrest reinforces a pattern: law enforcement agencies have shifted from reactive takedowns to proactive, intelligence-driven prosecution of botnet operators regardless of jurisdiction. The Kimwolf case demonstrates that running a DDoS-for-hire service — even from outside U.S. borders — now carries genuine extradition risk. As IoT device proliferation continues to hand botnet operators an ever-expanding attack surface, the pressure on international legal frameworks to close jurisdictional gaps will only intensify. For would-be operators in the underground market, the message is unambiguous: the alias offers no real cover.

Editorial Note

The Hacker News is a reputable cybersecurity news source with generally reliable reporting on law enforcement actions and cybercriminal arrests. DoJ announcements regarding botnet operators are typically verified through official channels and press releases. The specific technical details about Kimwolf being a variant of AISURU and the attribution to a 23-year-old Canadian named Jacob Butler (aka Dort) would be verifiable through official DoJ statements, though this summary appears truncated.

Claim Tracker

AI-assessed

VerifiedJacob Butler, 23, from Ottawa, Canada was arrested in connection with operating Kimwolf botnet

DoJ announcement confirmed this arrest on the stated date

UnverifiedKimwolf compromised more than one million devices worldwide

Based on allegations in court documents; not independently confirmed in excerpt

UnverifiedKimwolf struck targets including the U.S. Department of Defense

Alleged targeting mentioned but no specific incidents detailed or confirmed

UnverifiedKimwolf is a variant of AISURU botnet

Court documents state this assessment but technical verification not provided in article

VerifiedButler operated under the alias 'Dort'

Confirmed in DoJ charging documents referenced in article

Ask AI about this story

// discussion

sign in to join the discussion