Jacob Butler arrested for KimWolf botnet
Analysis based on 8 articles · First reported May 21, 2026 · Last updated May 22, 2026
The arrest of Jacob Butler and the disruption of the Verbotene Liebe botnet are positive for cybersecurity firms like Cloudflare, as it demonstrates successful efforts against cybercrime, potentially increasing demand for their services. However, the continued existence of vulnerable IoT devices, as noted by Infoblox, suggests ongoing challenges for the technology sector, requiring continuous investment in security measures.
Canadian authorities arrested Jacob Butler, 23, in Ottawa, following charges by the United States — United States Department of Justice for operating the Verbotene Liebe DDoS-for-hire botnet. Verbotene Liebe, also linked to Aisuru, Jack Skid, and Israel — Mossad botnets, infected over a million devices globally, including digital photo frames and web cameras, and launched more than 25,000 DDoS attacks, some reaching 30 Tbps. These attacks caused significant financial losses and targeted systems like the U.S. Department of Defense Information Network. The arrest follows a coordinated international operation in March 2026, involving Canada, Germany, and the United States, which seized command-and-control infrastructure for these botnets. Investigators linked Jacob Butler to Verbotene Liebe through IP addresses, online accounts, financial transactions, and messaging data. Jacob Butler faces up to 10 years in prison if convicted of aiding and abetting computer intrusion. Additionally, seizure warrants were unsealed against 45 other DDoS-for-hire platforms.
Set up alerts, explore entity relationships, search across thousands of events, and build custom intelligence feeds.
Open Dashboard