US and Canadian authorities arrest 23-year-old Jacob Butler, known online as “Dort”, for allegedly operating the Kimwolf DDoS botnet, which infected ~2M devices
Context & Ripple Effects
The arrest follows a March DOJ operation that disrupted four botnets infecting more than 3 million devices, including Kimwolf and Aisuru. Those botnets had been linked to a 31.4 Tbps DDoS attack in late 2025.
Related coverage also documented Kimwolf’s scale—more than 26,000 attacks against 8,000-plus victims—and an independent effort that helped uncover it. The case extends the response from infrastructure disruption to an alleged operator.
First-order effects
- Jacob Butler now faces US-Canadian law-enforcement action over allegations that he operated Kimwolf, increasing legal pressure on the botnet’s alleged leadership.
- The arrest gives investigators a potential route to evidence about Kimwolf’s operation and the devices infected by it, alongside the earlier disruption effort.
Second-order effects
- Combining botnet disruption with an operator arrest can make it harder to quickly reconstitute the same service, because both its infrastructure and alleged controller are under pressure.
- The case reinforces the value of coordination among authorities and outside researchers in identifying large DDoS operations and connecting them to individuals.
Third-order effects
- If this sequence becomes repeatable, botnet enforcement will increasingly pair technical takedowns with cross-border attribution and prosecutions rather than treating disruption as the endpoint.
- The recurrence of large botnets—from Andromeda’s earlier takedown to Kimwolf—suggests that removing infected-device networks remains an ongoing security problem even when individual operations are disrupted.
The trend: DDoS enforcement is shifting toward coordinated campaigns that combine infrastructure disruption, technical attribution, and alleged-operator arrests.