Skip to main content
COSMICBYTEZLABS
NewsSecurityHOWTOsToolsStudyTraining
ProjectsChecklistsAI RankingsNewsletterStatusTagsAbout
Subscribe

Press Enter to search or Esc to close

News
Security
HOWTOs
Tools
Study
Training
Projects
Checklists
AI Rankings
Newsletter
Status
Tags
About
RSS Feed
Reading List
Subscribe

Stay in the Loop

Get the latest security alerts, tutorials, and tech insights delivered to your inbox.

Subscribe NowFree forever. No spam.
COSMICBYTEZLABS

Your trusted source for IT intelligence, cybersecurity insights, and hands-on technical guides.

1154+ Articles
126+ Guides

CONTENT

  • Latest News
  • Security Alerts
  • HOWTOs
  • Projects
  • Exam Prep

RESOURCES

  • Search
  • Browse Tags
  • Newsletter Archive
  • Reading List
  • RSS Feed

COMPANY

  • About Us
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 CosmicBytez Labs. All rights reserved.

System Status: Operational
  1. Home
  2. News
  3. Alleged Kimwolf Botmaster 'Dort' Arrested, Charged in U.S. and Canada
Alleged Kimwolf Botmaster 'Dort' Arrested, Charged in U.S. and Canada
NEWS

Alleged Kimwolf Botmaster 'Dort' Arrested, Charged in U.S. and Canada

Canadian authorities arrested a 23-year-old Ottawa man suspected of building and operating Kimwolf, an IoT botnet that enslaved millions of devices for...

Dylan H.

News Desk

May 22, 2026
5 min read

Overview

Canadian authorities have arrested a 23-year-old Ottawa man on suspicion of building and operating Kimwolf, a fast-spreading Internet-of-Things (IoT) botnet responsible for enslaving millions of devices and conducting a series of massive distributed denial-of-service (DDoS) attacks over the past six months.

The suspect, known online as "Dort," faces charges in both the United States and Canada. The arrest marks a significant law enforcement action against one of the most disruptive botnet operations observed in the first half of 2026.


What Is Kimwolf?

Kimwolf is an IoT botnet that rapidly propagated across internet-connected devices — including home routers, IP cameras, and other embedded systems — to build a massive network of compromised machines controllable by a single operator.

AttributeDetail
Botnet nameKimwolf
Operator alias"Dort"
Suspect23-year-old man, Ottawa, Canada
Active periodApproximately six months prior to arrest
Target devicesIoT devices (routers, cameras, embedded systems)
Primary capabilityLarge-scale DDoS attacks
ChargesFiled in U.S. and Canada

The botnet was described as fast-spreading, leveraging common IoT vulnerabilities and default credentials to rapidly enlist new devices without user interaction. Once enslaved, devices joined the Kimwolf command-and-control (C2) infrastructure and were directed to participate in volumetric DDoS attacks against targeted victims.


The DDoS Attacks

Kimwolf was responsible for a series of massive DDoS attacks during its operational period, described as record-scale events. IoT botnets of this type generate attack traffic by directing thousands or millions of infected devices to simultaneously flood a target with requests, overwhelming their network capacity.

Key characteristics of Kimwolf-attributed attacks:

  • Volumetric DDoS — sheer traffic volume designed to exhaust bandwidth and infrastructure
  • Distributed origin — attack traffic sourced from millions of globally distributed IoT devices, making IP-based blocking ineffective
  • Record scale — attacks were described as among the largest seen in the six-month operational window

The targets of specific Kimwolf attacks have not been publicly detailed, but law enforcement coordination between the U.S. and Canada suggests the attacks affected victims or infrastructure in both countries.


The Arrest

Canadian authorities conducted the arrest following an investigation that involved cooperation between U.S. and Canadian law enforcement agencies. The joint nature of the charges — filed in both jurisdictions — reflects the cross-border impact of the Kimwolf DDoS campaigns.

At 23 years old, the alleged operator fits the profile of young technical operators who build sophisticated cybercrime infrastructure, often while operating from residential addresses. The Ottawa arrest is consistent with patterns seen in prior IoT botnet takedowns, where operators are identified through a combination of operational security failures, network forensics, and inter-agency intelligence sharing.


Why IoT Botnets Remain a Persistent Threat

The Kimwolf arrest highlights an enduring challenge in cybersecurity: IoT devices represent a massive, poorly secured attack surface that botnet operators continue to exploit.

FactorImpact
Default credentialsMillions of devices ship with unchanged default passwords, trivial to exploit
No patch mechanismMany IoT devices receive no firmware updates after manufacture
Always-on connectivityDevices maintain persistent internet connections without monitoring
User unawarenessOwners rarely notice when home devices are compromised
Scale potentialBillions of IoT devices globally — a virtually unlimited botnet recruitment pool

The Kimwolf case underscores the need for both consumer IoT security improvements (mandatory unique passwords, automatic updates) and ISP-level intervention to detect and quarantine compromised devices before they can participate in attack traffic.


Law Enforcement Signal

The joint U.S.-Canada prosecution sends a clear message to IoT botnet operators: geographic borders do not provide protection when attacks cross jurisdictions. Law enforcement agencies in both countries have demonstrated capacity and willingness to coordinate on cybercrime investigations regardless of where the operator physically resides.

Prior IoT botnet operators have faced significant prison sentences — the Mirai botnet creators, for example, cooperated with the FBI and received sentences of community service and supervised release. More recent prosecutions have trended toward custodial sentences as courts recognize the scale of harm caused by DDoS infrastructure.


Immediate Impact

  • Kimwolf botnet disrupted — with the alleged operator in custody, the C2 infrastructure that directed attacks is expected to go offline or lose coordination
  • Victim recovery — organizations targeted by Kimwolf DDoS attacks should review their incident records and ensure any infrastructure changes made under attack pressure are reverted or reviewed
  • IoT device owners — users of commonly targeted devices (routers, IP cameras, NAS) should change default passwords and apply firmware updates to remove any potential Kimwolf infections

Sources

  • KrebsOnSecurity — Alleged Kimwolf Botmaster 'Dort' Arrested, Charged in U.S. and Canada

Related Reading

  • ThreatsDay Bulletin: Linux Rootkits, Router 0-Day, AI Intrusions
  • Operation PowerOff Seizes 53 DDoS Domains
  • DoJ Disrupts 3 Million Device IoT Botnets
#Kimwolf#Botnet#DDoS#IoT Security#Arrest#Law Enforcement#Cybercrime#Canada#KrebsOnSecurity

Related Articles

Canadian Man Arrested and Charged for Running KimWolf DDoS Botnet

Jacob Butler, a Canadian national, has been arrested and charged in the United States and Canada for running the KimWolf DDoS-for-hire botnet, which...

5 min read

US and Canada Arrest and Charge Suspected Kimwolf Botnet Admin

U.S. and Canadian authorities arrested and charged a Canadian man with operating the Kimwolf DDoS botnet, which infected nearly two million devices...

4 min read

DoJ Disrupts 3 Million-Device IoT Botnets Behind Record 31.4 Tbps Global DDoS Attacks

The U.S. Department of Justice, in coordination with Germany and Canada, has dismantled the C2 infrastructure of four major IoT botnets — AISURU, Kimwolf,...

6 min read
Back to all News