Ottawa 23-Year-Old Charged as 'Dort,' Alleged Operator of the 30 Tbps Kimwolf IoT Botnet

Jacob Butler is in OPP custody on a U.S. extradition warrant. Prosecutors say his botnet pushed nearly 30 terabits per second. The questions I sent his lawyer remain unanswered.

ThreatVectr Newsdesk· 3 min read
Ottawa 23-Year-Old Charged as 'Dort,' Alleged Operator of the 30 Tbps Kimwolf IoT Botnet
Share

Ontario Provincial Police arrested Jacob Butler, 23, at an Ottawa address on Wednesday, and a sealed criminal complaint out of an Alaska district court was made public the same day. He is charged in the United States with aiding and abetting computer intrusion for allegedly running Kimwolf, the IoT botnet that the Department of Justice says generated DDoS attacks measured at close to 30 terabits per second across the past six months.

Butler, known online as "Dort," faces three Canadian charges as well: unauthorized use of a computer, possession of a device to obtain unauthorized use of a computer system, and mischief in relation to computer data. He remains in custody until a May 26 hearing.

The DOJ statement credits the Ontario Provincial Police, the FBI's Anchorage field office, and the Defense Criminal Investigative Service. DCIS is involved because Kimwolf traffic, prosecutors allege, hit Department of Defense IP space. The statement says the botnet issued more than 25,000 attack commands and that some victims lost over one million dollars. It does not name those victims. I asked DOJ press twice on Wednesday afternoon to identify even one. No response by deadline.

Kimwolf's infrastructure was seized on March 19, alongside three competing IoT botnets — Aisuru, JackSkid and Mossad — all fishing in the same pond of unpatched cameras, NVRs and digital photo frames. The DOJ statement does not say how many devices were freed by the takedown, or whether reinfection has been observed since. (The FBI Anchorage public affairs office said it was "not in a position to comment on operational specifics.")

One name in the complaint deserves attention. Investigators say Butler ordered a swatting attack against Ben Brundage, founder of the security startup Synthient, which helped close the IoT flaw Kimwolf was abusing to spread. "Hopefully this will end the harassment," Brundage said. He has been the target of at least two swattings that Dort publicly claimed.

The complaint (filed under seal in the District of Alaska, unsealed Wednesday) describes the kind of operational hygiene failure that has sunk a generation of teenage botmasters: shared IP addresses, reused account handles, payment trails, and Discord messages tied back to a single real-world identity. So much for tradecraft.

If extradited and convicted in the U.S., Butler faces up to 10 years. Sentencing guidelines would likely bring that down considerably given his age and lack of prior record.

Butler's Canadian counsel has not been listed on the public docket. I sent a request for comment to an email address tied to Butler in the complaint. It bounced. The DOJ has not said which of the four-dozen DDoS-for-hire domains seized in April were the one it claims collaborated with Kimwolf. That name is still sealed. Why?

© 2026 Threat Vectr