/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

US and Canadian authorities arrest 23-year-old Jacob Butler, known online as “Dort”, for allegedly operating the Kimwolf DDoS botnet, which infected ~2M devices

U.S. and Canadian authorities arrested and charged a Canadian man with operating the KimWolf distributed denial-of-service …

BleepingComputer Sergiu Gatlan

Context & Ripple Effects

Related coverage traced Kimwolf from its role alongside Aisuru in a 31.4 Tbps DDoS attack in late 2025 to a DOJ-led disruption of four botnets affecting more than 3 million devices. Independent research by Benjamin Brundage had also documented Kimwolf's use in more than 26,000 attacks against over 8,000 victims.

The arrest adds an alleged operator-level enforcement action to that infrastructure disruption, linking technical botnet investigations with cross-border criminal prosecution.

First-order effects

  • Jacob Butler now faces U.S. and Canadian charges alleging he operated Kimwolf, while investigators gain a path to pursue evidence, infrastructure, and alleged associates connected to the botnet.
  • Organizations targeted by Kimwolf face an immediate reduction in risk from that specific alleged operation, following the earlier disruption of the broader botnet set.

Second-order effects

  • DDoS-defense providers and operators of exposed devices will need to account for residual or reconstituted botnet capacity rather than treating a disruption and arrest as a permanent removal of the underlying device pool.
  • The case raises the operational cost for botnet operators by showing that public research, infrastructure takedowns, and international law enforcement can combine into attribution and prosecution.

Third-order effects

  • If enforcement repeatedly pairs botnet disruption with operator identification, DDoS activity may become more fragmented and short-lived rather than disappearing, shifting defense toward continuous mitigation and device remediation.
  • The scale of the attacks tied to Kimwolf and Aisuru underscores that internet-wide insecurity in connected devices remains a systemic DDoS risk even when individual operators are removed.

The trend: Botnet enforcement is moving from isolated takedowns toward coordinated campaigns that combine technical disruption, outside research, and cross-border prosecution.

Discussion

  • Phil Fuster Phil Fuster on linkedin
    Proud to see SpyCloud recognized by the U.S. Department of Justice for our assistance in the investigation and operation related to the KimWolf DDoS IoT botnet. …
  • Jason Lancaster Jason Lancaster on linkedin
    Yesterday, Canadian authorities arrested the alleged administrator of the KimWolf DDoS-for-hire botnet — a service that infected over a million IoT devices …