US and Canadian authorities arrest 23-year-old Jacob Butler, known online as “Dort”, for allegedly operating the Kimwolf DDoS botnet, which infected ~2M devices
U.S. and Canadian authorities arrested and charged a Canadian man with operating the KimWolf distributed denial-of-service …
Context & Ripple Effects
Related coverage traced Kimwolf from its role alongside Aisuru in a 31.4 Tbps DDoS attack in late 2025 to a DOJ-led disruption of four botnets affecting more than 3 million devices. Independent research by Benjamin Brundage had also documented Kimwolf's use in more than 26,000 attacks against over 8,000 victims.
The arrest adds an alleged operator-level enforcement action to that infrastructure disruption, linking technical botnet investigations with cross-border criminal prosecution.
First-order effects
- Jacob Butler now faces U.S. and Canadian charges alleging he operated Kimwolf, while investigators gain a path to pursue evidence, infrastructure, and alleged associates connected to the botnet.
- Organizations targeted by Kimwolf face an immediate reduction in risk from that specific alleged operation, following the earlier disruption of the broader botnet set.
Second-order effects
- DDoS-defense providers and operators of exposed devices will need to account for residual or reconstituted botnet capacity rather than treating a disruption and arrest as a permanent removal of the underlying device pool.
- The case raises the operational cost for botnet operators by showing that public research, infrastructure takedowns, and international law enforcement can combine into attribution and prosecution.
Third-order effects
- If enforcement repeatedly pairs botnet disruption with operator identification, DDoS activity may become more fragmented and short-lived rather than disappearing, shifting defense toward continuous mitigation and device remediation.
- The scale of the attacks tied to Kimwolf and Aisuru underscores that internet-wide insecurity in connected devices remains a systemic DDoS risk even when individual operators are removed.
The trend: Botnet enforcement is moving from isolated takedowns toward coordinated campaigns that combine technical disruption, outside research, and cross-border prosecution.