Alleged Kimwolf Botmaster ‘Dort’ Arrested, Charged in U.S. and Canada
It is a strange reality of the modern age that a 23-year-old sitting in a bedroom in Ottawa, Canada, can effectively throw a digital wrench into the gears of the United States Department of Defense and the fallout ends up landing right here in the Alaska District Court. When we hear about “botnets,” it often sounds like something out of a low-budget sci-fi flick, but the arrest of Jacob Butler—known in the darker corners of the web as “Dort”—proves that the distance between a digital photo frame in your living room and a federal crime scene in Anchorage is much shorter than we’d like to believe.
For those of us keeping an eye on the local landscape, the connection to Anchorage isn’t accidental. The FBI field office here in Anchorage, working alongside the Defense Criminal Investigative Service (DCIS), has been instrumental in untangling the web of the Kimwolf botnet. This wasn’t just a nuisance. we are talking about a coordinated effort that enslaved millions of Internet-of-Things (IoT) devices. The scale is almost hard to wrap your head around—the Justice Department reported DDoS attacks peaking at nearly 30 Terabits per second. To put that in perspective, that is a record-shattering volume of traffic designed to crush servers into submission, resulting in financial losses exceeding a million dollars for some victims.
What makes the Kimwolf case particularly insidious is the target. Butler didn’t just go after big banks or flashy corporations. He targeted devices that most of us consider “safe” or “firewalled,” like web cameras and those digital photo frames that cycle through family pictures. By exploiting critical security weaknesses—some of which were identified and patched by the team at Synthient—Butler turned mundane household objects into a rented army. These devices were then leased out to other cybercriminals or used to assault Internet address ranges belonging to the Department of Defense. Given the strategic importance of military installations like Joint Base Elmendorf-Richardson (JBER) and the surrounding defense infrastructure in Alaska, any attack on DoD address ranges is treated with the utmost urgency by federal authorities.
But the technical prowess of the Kimwolf botnet was marred by a very human kind of arrogance. While Butler had the skill to scale a network to millions of devices, he lacked the discipline to stay anonymous. He did what many “script kiddies” do: he let his ego take the wheel. After KrebsOnSecurity unmasked him in February 2026, Butler didn’t go quiet. Instead, he launched a campaign of doxing and swatting—the dangerous practice of calling in fake emergency reports to send armed police to someone’s home. He specifically targeted Ben Brundage, the founder of Synthient, simply because Brundage’s company helped close the security hole that Kimwolf relied on. It’s a classic case of a technical genius acting like a spoiled teenager, and that emotional volatility is exactly what left a trail of IP addresses and transaction records for the FBI to follow.
The takedown of Kimwolf wasn’t a solo effort. On March 19, U.S. Authorities joined an international coalition to seize the infrastructure of Kimwolf and three other competing botnets: Aisuru, JackSkid, and Mossad. It turns out the cybercrime world is just as competitive as any other market; these four botnets were essentially fighting over the same pool of vulnerable IoT devices. This “botnet war” highlights a systemic failure in how we manufacture smart devices. We prioritize convenience and low cost over basic security, creating a playground for people like Butler. If you’ve ever wondered why your “smart” lightbulb requires an account and a password but doesn’t seem to have a way to update its firmware, you’re looking at the exact vulnerability that fuels these botnets.
Now, seeing the FBI in Anchorage get involved in a case originating in Canada might make the threat feel distant, but the vulnerability is local. Every time a tiny business in downtown Anchorage or a home in Eagle River plugs in an unsecured IoT device, they are potentially adding a soldier to the next botnet. If you’re running a business or managing a home network, you can’t rely on the manufacturer’s “out-of-the-box” settings. You need to be proactive about network segmentation—keeping your “smart” gadgets on a separate VLAN so that if a photo frame gets compromised, the hacker can’t jump over to your point-of-sale system or your personal laptop.
Given my background in analyzing these digital trends and their local impacts, it’s clear that the “Dort” saga is a wake-up call for the Anchorage community. We are a hub for defense and logistics, making us a high-value target for the kind of disruption Butler sought. If you feel your current setup is a bit too “plug-and-play” for comfort, it’s time to bring in some professional eyes. You don’t need a federal task force, but you do need a strategy.
If this trend impacts you or your business in the Anchorage area, here are the three types of local professionals Make sure to be looking for to harden your defenses:

- Managed Security Service Providers (MSSPs): For small to mid-sized businesses, you don’t need a full-time CISO, but you do need someone watching the perimeter. Look for an MSSP that specializes in 24/7 monitoring and adheres to the NIST Cybersecurity Framework. They should be able to provide “threat hunting” services rather than just installing a firewall and walking away.
- IoT Security Auditors: If you operate a facility with a high density of connected devices (like a modern warehouse or a medical clinic), seek out a specialist auditor. The key criterion here is “firmware analysis” capability. You want someone who can actually test the hardware’s resilience against the kind of exploits used by Kimwolf, not just someone who scans your Wi-Fi password.
- Digital Forensics & Incident Response (DFIR) Consultants: Hope for the best, but plan for the worst. A DFIR expert is the person you call when you suspect you’ve already been breached. When hiring locally, prioritize those with experience collaborating with federal agencies or those who hold certifications like the GCFA (GIAC Certified Forensic Analyst). They ensure that if you have to report a breach, the evidence is preserved in a way that is legally admissible.
The arrest of Jacob Butler is a win for the “good guys,” but the infrastructure of the IoT world remains a minefield. The best defense isn’t waiting for the FBI to make an arrest in another country; it’s making sure your own front door is locked.
Ready to find trusted professionals? Browse our complete directory of top-rated alittlesunshine,ddosforhire,internetofthings(iot),neerdowellnews,aisuru,defensecriminalinvestigativeservice,departmentofdefense,dort,jackskid,jacobbutler,kimwolf,mossad,ontarioprovincialpolice experts in the Anchorage area today.