Close Menu
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice

Subscribe to Updates

Get the latest creative news from FooBar about art, design and business.

What's Hot

Megalodon GitHub Attack Targets 5,561 Repos with Malicious CI/CD Workflows

May 31, 2026

Making Vulnerable Drivers Exploitable Without Hardware

May 31, 2026

Kimwolf DDoS Botnet Operator Arrested in Canada Over DDoS-for-Hire Attacks

May 31, 2026
Facebook X (Twitter) Instagram
Sunday, May 31
Facebook X (Twitter) Instagram Pinterest Vimeo
Cyberwire Daily
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice
Cyberwire Daily
Home»News»Kimwolf DDoS Botnet Operator Arrested in Canada Over DDoS-for-Hire Attacks
News

Kimwolf DDoS Botnet Operator Arrested in Canada Over DDoS-for-Hire Attacks

Team-CWDBy Team-CWDMay 31, 2026No Comments2 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
Share
Facebook Twitter LinkedIn Pinterest Email


The U.S. Department of Justice (DoJ) on Thursday announced the arrest of a Canadian man in connection with allegedly operating a distributed denial-of-service (DDoS) botnet known as Kimwolf.

In tandem, Jacob Butler (aka Dort), 23, Ottawa, Canada, has been charged with offenses related to the development and operation of the botnet. Kimwolf is assessed to be a variant of AISURU that specifically infected Android devices with an exposed Android Debug Bridge (ADB) service.

“Kimwolf targeted infected devices which were traditionally ‘firewalled’ from the rest of the internet, such as digital photo frames and web cameras,” the DoJ said. “The infected devices were enslaved by the botnet operators.”

“The operators then used a ‘cybercrime-as-a-service’ model to sell access to the infected devices to other cybercriminals. The operators and their customers forced the victim devices to participate in DDoS attacks, targeting computers and servers located throughout the world, including Department of Defense Information Network (DoDIN) IP addresses.”

Court documents show that Butler was linked to the administration of the Kimwolf botnet through IP address, online account information, and Discord message records posted by an account called resi[.]to.

That Butler was behind the Kimwolf botnet was first exposed by independent security journalist Brian Krebs earlier this February. At that time, the defendant claimed that he had not used the “Dort” persona since 2021 and that some other party was impersonating him after compromising his old account.

The charges come exactly two months after U.S. authorities, in partnership with Canada and Germany, disrupted the command-and-control (C2) infrastructure associated with Kimwolf, AISURU, JackSkid, and Mossad as part of a court-authorized law enforcement operation.

Per the DoJ, Kimwolf is estimated to have issued over 25,000 attack commands. Prior to their takedown, the AISURU/Kimwolf botnets were attributed to some of the record-setting DDoS attacks to date, flooding targets with junk traffic that peaked at 31.4 Terabits per second (Tbps).

Besides Butler’s arrest, seizure warrants have been unsealed targeting online services supporting 45 DDoS-for-hire platforms, allowing law enforcement to dismantle them. One of the platforms is said to have collaborated with Kimwolf.

Butler has been charged with one count of aiding and abetting computer intrusion. If convicted, he faces up to 10 years in prison.



Source

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleCISA Adds Exploited Langflow and Trend Micro Apex One Vulnerabilities to KEV
Next Article Making Vulnerable Drivers Exploitable Without Hardware
Team-CWD
  • Website

Related Posts

News

Megalodon GitHub Attack Targets 5,561 Repos with Malicious CI/CD Workflows

May 31, 2026
News

Making Vulnerable Drivers Exploitable Without Hardware

May 31, 2026
News

CISA Adds Exploited Langflow and Trend Micro Apex One Vulnerabilities to KEV

May 31, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest News

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202522 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures

April 29, 202610 Views

Why SOC Burnout Can Be Avoided: Practical Steps

November 14, 20259 Views

Cyber M&A Roundup: Cyber Giants Strengthen AI Security Offerings

December 1, 20258 Views
Stay In Touch
  • Facebook
  • YouTube
  • TikTok
  • WhatsApp
  • Twitter
  • Instagram
Most Popular

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202522 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures

April 29, 202610 Views
Our Picks

A stealthy RAT burrowing deep into Android devices

May 26, 2026

Can password managers get hacked? Here’s what to know

November 14, 2025

Scams target soccer fans with fake World Cup tickets, merchandise

May 22, 2026

Subscribe to Updates

Get the latest news from cyberwiredaily.com

Facebook X (Twitter) Instagram Pinterest
  • Home
  • Contact
  • Privacy Policy
  • Terms of Use
  • California Consumer Privacy Act (CCPA)
© 2026 All rights reserved.

Type above and press Enter to search. Press Esc to cancel.