Justice Department Charges Ottawa Man With Operating Kimwolf DDoS Botnet

Federal prosecutors say Jacob Butler, 23, developed and rented out a variant of the AISURU botnet for paid denial-of-service attacks.

ThreatVectr Newsdesk· 2 min read
Justice Department Charges Ottawa Man With Operating Kimwolf DDoS Botnet
Share

The United States Department of Justice (DOJ) on Thursday announced the arrest of a 23-year-old Ottawa resident accused of building and operating Kimwolf, a distributed denial-of-service (DDoS) botnet that prosecutors describe as a derivative of the AISURU malware family. Jacob Butler, who allegedly used the online handle "Dort," faces charges tied to the development of the botnet and the sale of attack capacity to paying customers.

The complaint, filed in federal court, alleges that Butler conspired with others to compromise internet-connected devices, marshal them into a command-and-control infrastructure, and direct floods of traffic at victim networks on behalf of clients who paid for the service. AISURU, the parent strain from which Kimwolf is assessed to be derived, has been tracked by network defenders for several months as a successor in the long lineage of Mirai-descended IoT botnets.

Under the federal computer fraud statutes cited in the charging documents, the offenses carry significant custodial exposure if proven at trial. The DOJ's announcement frames the arrest as part of a continuing effort, coordinated with Canadian authorities, to identify operators of booter and stresser services who rent attack infrastructure to anyone willing to pay.

The agency has not yet released the indictment in full, and the affidavit supporting the complaint remains the principal public record of the allegations. Counsel for Butler has not been listed on the public docket.

DDoS-for-hire prosecutions have followed a predictable cadence in recent years. The Federal Bureau of Investigation (FBI) and DOJ seized dozens of booter domains in Operation PowerOFF, a recurring takedown effort now in its sixth iteration, and several operators have been sentenced to terms ranging from probation to multi-year prison sentences. The Cybersecurity and Infrastructure Security Agency (CISA) has also issued guidance to public-sector entities on absorbing and mitigating volumetric attacks, which it lists among the more common disruptive techniques aimed at state and local government services.

Kimwolf itself, according to researchers tracking the AISURU family, focused on conscripting consumer routers and IP cameras with weak or default credentials. The economics are unchanged from earlier generations. Cheap devices, indifferent firmware maintenance, and a willing customer base for short, sharp floods aimed at gaming opponents, business competitors, and the occasional public-facing government site.

Butler is expected to appear before a Canadian court in the coming weeks as the United States pursues extradition. Prosecutors will need to file a formal extradition request through the Department of Justice's Office of International Affairs, after which the matter moves to proceedings under the Canadian Extradition Act. No trial date has been set.

© 2026 Threat Vectr