/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

US and Canadian authorities arrest 23-year-old Jacob Butler, known online as “Dort”, for allegedly operating the Kimwolf DDoS botnet, which infected ~2M devices

BleepingComputer Sergiu Gatlan

Context & Ripple Effects

The arrest follows a March DOJ operation that disrupted four botnets infecting more than 3 million devices, including Kimwolf and Aisuru. Those botnets had been linked to a 31.4 Tbps DDoS attack in late 2025.

Related coverage also documented Kimwolf’s scale—more than 26,000 attacks against 8,000-plus victims—and an independent effort that helped uncover it. The case extends the response from infrastructure disruption to an alleged operator.

First-order effects

  • Jacob Butler now faces US-Canadian law-enforcement action over allegations that he operated Kimwolf, increasing legal pressure on the botnet’s alleged leadership.
  • The arrest gives investigators a potential route to evidence about Kimwolf’s operation and the devices infected by it, alongside the earlier disruption effort.

Second-order effects

  • Combining botnet disruption with an operator arrest can make it harder to quickly reconstitute the same service, because both its infrastructure and alleged controller are under pressure.
  • The case reinforces the value of coordination among authorities and outside researchers in identifying large DDoS operations and connecting them to individuals.

Third-order effects

  • If this sequence becomes repeatable, botnet enforcement will increasingly pair technical takedowns with cross-border attribution and prosecutions rather than treating disruption as the endpoint.
  • The recurrence of large botnets—from Andromeda’s earlier takedown to Kimwolf—suggests that removing infected-device networks remains an ongoing security problem even when individual operations are disrupted.

The trend: DDoS enforcement is shifting toward coordinated campaigns that combine infrastructure disruption, technical attribution, and alleged-operator arrests.

Discussion

  • Jason Lancaster Jason Lancaster on linkedin
    Yesterday, Canadian authorities arrested the alleged administrator of the KimWolf DDoS-for-hire botnet — a service that infected over a million IoT devices …
  • Phil Fuster Phil Fuster on linkedin
    Proud to see SpyCloud recognized by the U.S. Department of Justice for our assistance in the investigation and operation related to the KimWolf DDoS IoT botnet. …
  • Matthew Ellwood Matthew Ellwood on linkedin
    Proud to see the recent media release from the DOJ highlighting the results of an international cybercrime investigation that our team was involved …