The Kimwolf Botnet and the Pursuit of Its Operator, “There”
In early January 2026, the security community focused on the Kimwolf botnet, a rapidly expanding network of compromised devices. The attention stemmed not only from its size—estimated at over 2 million infected systems globally—but also from the aggressive actions taken by the individual believed to be controlling it, known online as “There.” This article details the ongoing investigation into “There,” the attacks launched against researchers, and the emerging connections to a Canadian hacker.
The Kimwolf Botnet: A Global Threat
The Kimwolf botnet, first detailed by KrebsOnSecurity in January 2026, has become a significant threat to internet security. It leverages compromised devices, particularly Android TV boxes, to relay malicious traffic, including ad fraud, account takeover attempts, and distributed denial-of-service (DDoS) attacks. The botnet’s unique method of spreading—tunneling through residential proxy networks to infect devices behind firewalls—makes it particularly dangerous. Concentrations of infected devices have been identified in Vietnam, Brazil, India, Saudi Arabia, Russia, and the United States.
Retaliation and Escalation
The initial exposure of Kimwolf’s tactics by security researcher Benjamin Brundage, founder of Synthient, triggered a series of retaliatory attacks by “There.” These attacks included DDoS attacks, doxing (the public release of personal information), and email flooding directed at Brundage and KrebsOnSecurity. Most alarmingly, “There” orchestrated a swatting attempt against Brundage, resulting in a police response to his home based on false information.
Identifying “There”: From CPacket to Dort
Investigations into “There’s” identity have revealed a complex web of online aliases and activities. A 2020 public “dox” identified “There” as a Canadian teenager born in August 2003, using the aliases “CPacket” and “M1ce.” Open-source intelligence (OSINT) research reveals a GitHub account linked to Dort and CPacket, created in 2017 with the email address jay.miner232@gmail.com.
Cyber intelligence firm Intel 471 connected this email address to accounts on cybercrime forums, including Nulled (“Uubuntuu”) and Cracked (“Dorted”), both originating from the same IP address at Rogers Canada (99.241.112.24). “There” also operated under the nickname DortDev, active in March 2022 on the SLIP$ chat server, offering disposable email addresses and CAPTCHA bypass services used in SIM-swapping and account takeover schemes.
The Connection to Jacob Butler
Further investigation suggests a link between “There” and an individual named Jacob Butler. Flashpoint indexed posts on the SIM Land Telegram channel from Dort collaborating with someone identified as “Qoft.” Qoft stated they had stolen over $250,000 worth of Microsoft Xbox Game Pass accounts with Dort, using stolen payment card data. The email address associated with “There,” jay.miner232@gmail.com, was also used by Jacob Butler (jacobbutler803@gmail.com).
DomainTools.com records show jacobbutler803@gmail.com was used to register Minecraft-themed domains in 2015, linked to Jacob Butler in Ottawa, Canada, and a specific phone number (613-909-9727). Additional accounts under the alias “M1CE” on Minecraft and Nulled were also connected to this email address, sharing passwords with jay.miner232@gmail.com and an Ottawa-Carleton District School Board email address.
Conflicting Accounts and Voice Analysis
When contacted, Jacob Butler acknowledged creating a Minecraft cheat long ago but denied involvement in Dortsolver or any activity attributed to the “Dort” alias after 2021. He claimed his accounts may have been compromised and expressed concern about being targeted again. However, a voice comparison between Butler’s recent phone conversation and a 2022 Clash of Code competition recording featuring “Dort” revealed striking similarities, including a similar cursing style present in a recent diss track threatening Brundage.
Butler suggested the voice in the competition recording may be an impersonator using a voice changer, claiming his voice had been cloned previously.
Ongoing Investigation
The investigation into “There” and the Kimwolf botnet remains active. The aggressive tactics employed by “There” highlight the risks faced by security researchers and the potential for real-world harm resulting from cybercrime. The connections to Jacob Butler, while contested, represent a significant lead in identifying the individual behind this widespread threat.