DoJ Disrupts Kimwolf Botnet: 3 Million Devices Behind DDoS Attacks
The U.S. Department of Justice announced on March 20, 2026, a major international law enforcement operation that disrupted command-and-control infrastructure powering four massive IoT botnets. This operation successfully dismantled the Kimwolf botnet along with three others responsible for record-breaking distributed denial-of-service attacks reaching 31.4 terabits per second.
What Happened: DoJ Disrupts World’s Largest IoT Botnets
The U.S. Department of Justice executed a court-authorized operation targeting the infrastructure behind four major botnets. These include Kimwolf, AISURU, JackSkid, and Mossad. The operation represents one of the largest botnet disruptions in history.
International cooperation played a crucial role in this takedown. Canadian and German authorities assisted in targeting the operators. Private sector firms including Akamai, Amazon Web Services, Cloudflare, DigitalOcean, Google, Lumen, Nokia, Okta, Oracle, PayPal, SpyCloud, Synthient, Team Cymru, Unit 221B, and QiAnXin XLab provided essential support.
Technical Details of the Botnets
The four botnets collectively infected more than three million devices worldwide. These compromised devices included digital video recorders, web cameras, Wi-Fi routers, Android smart TVs, and set-top boxes. Hundreds of thousands of these infected devices were located within the United States.
Kimwolf represented a significant evolution in botnet tactics. Unlike traditional botnets that scan the open internet for vulnerable devices, Kimwolf exploited residential proxy networks to infiltrate home networks. The botnet gained access through compromised streaming TV boxes and IoT devices with Android Debug Bridge exposed.
Attack Scale and Impact
The combined botnets issued hundreds of thousands of DDoS attack commands:
- AISURU: Over 200,000 DDoS attack commands
- Kimwolf: Over 25,000 DDoS attack commands
- JackSkid: Over 90,000 DDoS attack commands
- Mossad: Over 1,000 DDoS attack commands
The November 2025 attack peaked at 31.4 Tbps. Cloudflare described this traffic as equivalent to the combined populations of the UK, Germany, and Spain all simultaneously typing a website address and hitting enter at the same second. The attack lasted only 35 seconds but demonstrated unprecedented scale.
Botnet Monetization Model
The operators employed a cybercrime-as-a-service model. They sold access to infected devices to other cybercriminals. These customers then used the botnet infrastructure to conduct DDoS attacks against targets worldwide. Some attackers demanded extortion payments from victims.
Business and Operational Impact
The impact of these botnets extended across multiple sectors. Akamai reported that the hyper-volumetric botnets generated attacks exceeding 30 Tbps, 14 billion packets per second, and 300 million requests per second. Such attacks can cripple core internet infrastructure.
Service degradation affected ISPs and their downstream customers. High-capacity cloud-based mitigation services faced challenges handling this volume. The economic impact included operational downtime, mitigation costs, and extortion payments.
Lumen Black Lotus Labs null-routed nearly 1,000 C2 servers used by AISURU and Kimwolf. JackSkid averaged over 150,000 daily victims in early March 2026, reaching 250,000 on March 8. Mossad averaged over 100,000 daily victims during the same period.
Attribution and Investigation
Independent security journalist Brian Krebs traced the Kimwolf administrator to a 23-year-old Jacob Butler from Ottawa, Canada. Butler claimed someone compromised his old account and impersonated him. Another prime suspect is reportedly a 15-year-old residing in Germany. No arrests have been announced as of the DoJ disclosure.
Multiple security firms contributed evidence to the investigation. XLab provided sample hashes, decrypted C2 configurations, and screenshots of DDoS attacks. The collaborative effort between law enforcement and private industry proved essential to this operation’s success.
Mitigation and Recommendations
Immediate Actions for Defenders
- Audit IoT devices: Inventory all connected devices including smart TVs, set-top boxes, cameras, and routers
- Disable Android Debug Bridge: Turn off ADB on Android devices unless specifically required for development
- Segment networks: Isolate IoT devices from critical business systems
- Monitor for infection indicators: Look for unusual outbound traffic patterns or connections to known C2 infrastructure
- Apply firmware updates: Patch all IoT devices with the latest manufacturer updates
Long-Term Security Measures
Organizations should implement zero-trust networking principles for IoT deployments. Additionally, network monitoring solutions must detect anomalous traffic patterns characteristic of botnet participation. Furthermore, security teams should maintain awareness of residential proxy network vulnerabilities that botnets exploit.
Bottom line: The Kimwolf takedown demonstrates both the scale of modern IoT botnet threats and the effectiveness of coordinated public-private partnerships. However, the vulnerability exploitation techniques used by these botnets continue to be emulated by new threats. Organizations must prioritize IoT security and network segmentation to prevent becoming part of the next massive botnet.
Incident Summary
| Incident: | Kimwolf/AISURU Botnet Takedown |
| Date Announced: | March 20, 2026 |
| Affected Devices: | 3+ million IoT devices (Android TVs, set-top boxes, DVRs, cameras, routers) |
| Botnets Disrupted: | Kimwolf, AISURU, JackSkid, Mossad |
| Peak Attack Size: | 31.4 Tbps (November 2025) |
| Attack Duration: | 35 seconds (record attack) |
| Primary Infection Vector: | Residential proxy networks, exposed Android Debug Bridge |
| Monetization: | Cybercrime-as-a-service model selling DDoS capabilities |
| Status: | C2 infrastructure disrupted via court-authorized operation |
References
- U.S. Department of Justice, “Authorities Disrupt World’s Largest IoT DDoS Botnets Responsible for Record-Breaking Attacks,” March 20, 2026, https://www.justice.gov/usao-ak/pr/authorities-disrupt-worlds-largest-iot-ddos-botnets-responsible-record-breaking-attacks
- The Hacker News, “DoJ Disrupts 3 Million-Device IoT Botnets Behind Record 31.4 Tbps Global DDoS Attacks,” March 20, 2026, https://thehackernews.com/2026/03/doj-disrupts-3-million-device-iot.html
- Cloudflare Blog, “DDoS Threat Report 2025 Q4,” February 2026, https://blog.cloudflare.com/ddos-threat-report-2025-q4/
- Krebs on Security, “Who Is the Kimwolf Botmaster ‘Dort’?” February 2026, https://krebsonsecurity.com/2026/02/who-is-the-kimwolf-botmaster-dort/
- Akamai Security Research, “Akamai Helps Disrupt World’s Largest IoT Botnets,” March 2026, https://www.akamai.com/blog/security-research/akamai-helps-disrupt-worlds-largest-iot-botnets