Botnet Kingpin Busted: How a 23-Year-Old From Ottawa Built a Two-Million-Device DDoS Empire
Jacob Butler, alleged administrator of the KimWolf botnet, faces extradition to the US after a joint law enforcement operation dismantled one of the most destructive DDoS-for-hire platforms ever tracked.
Written by OutOfToken AI
May 24, 2026 · 4 min read · Synthesized from reporting by BleepingComputer · How this works
US and Canadian authorities have arrested Jacob Butler, a 23-year-old Ottawa resident accused of running the KimWolf botnet — a distributed denial-of-service platform that commandeered more than two million devices across the globe. The US Justice Department filed an extradition warrant after Butler, known online as 'Dort,' was taken into custody in Canada on Wednesday following a coordinated international takedown earlier this year. The charges represent one of the most significant DDoS-infrastructure prosecutions in recent memory.
A Botnet Built for Hire
KimWolf wasn't a passive piece of malware — it was an active commercial service, offering paying customers the firepower to knock targets offline on demand. Investigators characterize it as a DDoS-for-hire operation, meaning Butler and any co-conspirators allegedly monetized the botnet's destructive capacity by selling attack packages to third parties. Court documents describe Butler as a principal administrator of the platform, with deep operational control over its infrastructure, command-and-control architecture, and client-facing services. The breadth of the operation drew scrutiny from the Defense Criminal Investigative Service, signaling that some of KimWolf's targets may have had connections to US defense or federal contracting interests.
Two Million Devices, One Clever Exploit
KimWolf's technical underpinning is what separates it from run-of-the-mill botnets. Researchers have identified it as a variant of the Aisuru botnet — itself a record-setting DDoS platform — but with a critical evolution: KimWolf's operators cracked a method to abuse residential-proxy networks for local device control, allowing the malware to spread aggressively across Android TV boxes. More than two million Android TV devices eventually fell under its influence. By hijacking consumer hardware embedded in home networks, KimWolf effectively laundered its attack traffic through millions of legitimate IP addresses, complicating both detection and mitigation for defenders. The residential-proxy abuse vector has become an increasingly favored technique among sophisticated botnet operators precisely because it defeats traditional IP-block-based defenses.
"KimWolf infected more than two million Android TV devices by exploiting residential-proxy networks — turning everyday living-room hardware into weapons for hire against targets worldwide."
International Machinery Grinds Into Gear
Butler's arrest followed the physical dismantling of KimWolf's infrastructure earlier in 2024, a takedown credited to a joint operation involving US federal agencies and the Royal Canadian Mounted Police. The extradition warrant filed by US prosecutors signals Washington's intent to try Butler on American soil under federal computer hacking statutes — a legal path that carries substantial prison exposure. The case underscores a maturing framework for cross-border cybercrime enforcement: where jurisdictional gaps once provided sanctuary for operators in friendly or uncooperative nations, Canada's extradition relationship with the US has increasingly closed that loophole for homegrown cybercriminals who target American infrastructure, businesses, or government systems.
The Butler arrest arrives as Western law enforcement agencies escalate pressure on the DDoS-for-hire ecosystem — a market that has long operated in a legal gray zone by claiming customers bear responsibility for attack targets. With KimWolf dismantled and its alleged operator now facing extradition, prosecutors are sending a clear message: building and monetizing attack infrastructure is conspiracy enough for federal charges, regardless of who pulls the trigger. For the operators of similar services still running, the math is changing fast — and Ottawa is no longer a safe distance from a US grand jury.
Editorial Note
BleepingComputer is a highly reputable cybersecurity news outlet with strong track record for accurate reporting on malware, botnets, and law enforcement actions. The Kimwolf botnet is a documented threat that has been tracked by security researchers, making the claim plausible. Cross-verification with official law enforcement statements (FBI, RCMP, or DOJ press releases) would confirm specific arrest and charging details.
Claim Tracker
AI-assessed
Personal details not independently confirmed in article; relies on US Justice Department/law enforcement sources
Specific device count attributed to investigators but no documentation provided; typical of law enforcement claims in press releases
Characterized as 'DDoS-for-hire' based on court documents and investigator characterization; actual payment evidence not detailed
Attribution based on law enforcement statements; no independent verification provided
Vague timeline ('earlier this year'); article incomplete, lacks specific operation details or dates
Ask AI about this story
// discussion
sign in to join the discussion