{"id":11037,"date":"2026-03-02T03:03:47","date_gmt":"2026-03-02T03:03:47","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2026\/03\/02\/who-is-the-kimwolf-botmaster-dort\/"},"modified":"2026-03-02T03:03:47","modified_gmt":"2026-03-02T03:03:47","slug":"who-is-the-kimwolf-botmaster-dort","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2026\/03\/02\/who-is-the-kimwolf-botmaster-dort\/","title":{"rendered":"Who is the Kimwolf Botmaster \u201cDort\u201d?"},"content":{"rendered":"<p>    Who is the Kimwolf Botmaster \u201cDort\u201d?<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>In early January 2026, KrebsOnSecurity revealed how a security researcher disclosed a vulnerability that was used to build <strong>Kimwolf<\/strong>, the world\u2019s largest and most disruptive botnet. Since then, the person in control of Kimwolf \u2014 who goes by the handle \u201c<strong>Dort<\/strong>\u201d \u2014 has coordinated a barrage of distributed denial-of-service (DDoS), doxing and email flooding attacks against the researcher and this author, and more recently caused a SWAT team to be sent to the researcher\u2019s home. This post examines what is knowable about Dort based on public information.<\/p>\n<p>A public \u201cdox\u201d created in 2020 asserted Dort was a teenager from Canada (DOB August 2003) who used the aliases \u201c<strong>CPacket<\/strong>\u201d and \u201c<strong>M1ce<\/strong>.\u201d A search on the username CPacket at the open source intelligence platform <strong>OSINT Industries<\/strong> finds a <strong>GitHub<\/strong> account under the names Dort and CPacket that was created in 2017 using the email address <strong>jay.miner232@gmail.com<\/strong>.<\/p>\n<div id=\"attachment_73247\" style=\"width: 759px\" class=\"wp-caption aligncenter\">\n<img data-recalc-dims=\"1\" loading=\"lazy\" aria-describedby=\"caption-attachment-73247\" decoding=\"async\" class=\" wp-image-73247\" src=\"https:\/\/i0.wp.com\/krebsonsecurity.com\/wp-content\/uploads\/2026\/02\/cpacket-discord.png?resize=749%2C537&#038;ssl=1\" alt=\"\" width=\"749\" height=\"537\" srcset=\"https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2026\/02\/cpacket-discord.png 988w, https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2026\/02\/cpacket-discord-768x551.png 768w, https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2026\/02\/cpacket-discord-782x561.png 782w\" sizes=\"(max-width: 749px) 100vw, 749px\"><\/p>\n<p id=\"caption-attachment-73247\" class=\"wp-caption-text\">Image: osint.industries.<\/p>\n<\/div>\n<p>The cyber intelligence firm <strong>Intel 471<\/strong> says jay.miner232@gmail.com was used between 2015 and 2019 to create accounts at multiple cybercrime forums, including <strong>Nulled<\/strong> (username \u201cUubuntuu\u201d) and <strong>Cracked <\/strong>(user \u201cDorted\u201d); Intel 471 reports that both of these accounts were created from the same Internet address at Rogers Canada (99.241.112.24).<\/p>\n<p>Dort was an extremely active player in the Microsoft game <strong>Minecraft<\/strong> who gained notoriety for their \u201c<strong>Dortware<\/strong>\u201d software that helped players cheat. But somewhere along the way, Dort graduated from hacking Minecraft games to enabling far more serious crimes.<\/p>\n<p>Dort also used the nickname <strong>DortDev<\/strong>, an identity that was active in March 2022 on the chat server for the prolific cybercrime group known as <a href=\"https:\/\/krebsonsecurity.com\/tag\/lapsus\/\" target=\"_blank\" rel=\"noopener\">LAPSUS$<\/a>. Dort peddled a service for registering temporary email addresses, as well as \u201c<a href=\"https:\/\/pypi.org\/project\/dort\/\" target=\"_blank\" rel=\"noopener\">Dortsolver<\/a>,\u201d code that could bypass various CAPTCHA services designed to prevent automated account abuse. Both of these offerings were advertised in 2022 on <strong>SIM Land<\/strong>, a Telegram channel dedicated to <a href=\"https:\/\/krebsonsecurity.com\/category\/sim-swapping\/\" target=\"_blank\" rel=\"noopener\">SIM-swapping<\/a> and account takeover activity.<\/p>\n<p>The cyber intelligence firm <strong>Flashpoint <\/strong>indexed 2022 posts on SIM Land by Dort that show this person developed the disposable email and CAPTCHA bypass services with the help of another hacker who went by the handle \u201c<strong>Qoft<\/strong>.\u201d<\/p>\n<p>\u201cI legit just work with Jacob,\u201d Qoft said in 2022 in reply to another user, referring to their exclusive business partner Dort. In the same conversation, Qoft bragged that the two had stolen more than $250,000 worth of <a href=\"https:\/\/www.xbox.com\/en-US\/xbox-game-pass\" target=\"_blank\" rel=\"noopener\">Microsoft Xbox Game Pass accounts<\/a> by developing a program that mass-created Game Pass identities using stolen payment card data.<span id=\"more-73057\"><\/span><\/p>\n<p>Who is the Jacob that Qoft referred to as their business partner? The breach tracking service <strong>Constella Intelligence<\/strong> finds the password used by jay.miner232@gmail.com was reused by just one other email address: <strong>jacobbutler803@gmail.com<\/strong>. Recall that the 2020 dox of Dort said their date of birth was August 2003 (8\/03).<\/p>\n<p>Searching this email address at <strong>DomainTools.com<\/strong> reveals it was used in 2015 to register several Minecraft-themed domains, all assigned to a Jacob Butler in Ottawa, Canada and to the Ottawa phone number 613-909-9727.<\/p>\n<p>Constella Intelligence finds jacobbutler803@gmail.com was used to register an account on the hacker forum Nulled in 2016, as well as the account name \u201cM1CE\u201d on Minecraft. Pivoting off the password used by their Nulled account shows it was shared by the email addresses<strong> j.a.y.m.iner232@gmail.com<\/strong> and <strong>jbutl3@ocdsb.ca<\/strong>, the latter being an address at a domain for the <strong>Ottawa-Carelton District School Board<\/strong>.<\/p>\n<p>Data indexed by the breach tracking service <strong>Spycloud<\/strong> suggests that at one point Jacob Butler shared a computer with his mother and a sibling, which might explain why their email accounts were connected to the password \u201cjacobsplugs.\u201d Neither Jacob nor any of the other Butler household members responded to requests for comment.<\/p>\n<p>The open source intelligence service <strong>Epieos<\/strong> finds jacobbutler803@gmail.com created the GitHub account \u201c<strong>MemeClient<\/strong>.\u201d Meanwhile, Flashpoint indexed a deleted anonymous Pastebin.com post from 2017 declaring that MemeClient was the creation of a user named CPacket \u2014 one of Dort\u2019s early monikers.<\/p>\n<p>Why is Dort so mad? On January 2, KrebsOnSecurity published <a href=\"https:\/\/krebsonsecurity.com\/2026\/01\/the-kimwolf-botnet-is-stalking-your-local-network\/\" target=\"_blank\" rel=\"noopener\">The Kimwolf Botnet is Stalking Your Local Network<\/a>, which explored research into the botnet by <strong>Benjamin Brundage<\/strong>, founder of the proxy tracking service <strong>Synthient<\/strong>. Brundage figured out that the Kimwolf botmasters were exploiting a little-known weakness in residential proxy services to infect poorly-defended devices \u2014 like TV boxes and digital photo frames \u2014 plugged into the internal, private networks of proxy endpoints.<\/p>\n<p>By the time that story went live, most of the vulnerable proxy providers had been notified by Brundage and had fixed the weaknesses in their systems. That vulnerability remediation process massively slowed Kimwolf\u2019s ability to spread, and within hours of the story\u2019s publication Dort created a Discord server in my name that began publishing personal information about and violent threats against Brundage, Yours Truly, and others.<\/p>\n<div id=\"attachment_73249\" style=\"width: 760px\" class=\"wp-caption aligncenter\">\n<img data-recalc-dims=\"1\" aria-describedby=\"caption-attachment-73249\" decoding=\"async\" loading=\"lazy\" class=\" wp-image-73249\" src=\"https:\/\/i0.wp.com\/krebsonsecurity.com\/wp-content\/uploads\/2026\/02\/ben-flyswat.png?resize=750%2C652&#038;ssl=1\" alt=\"\" width=\"750\" height=\"652\" srcset=\"https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2026\/02\/ben-flyswat.png 872w, https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2026\/02\/ben-flyswat-768x668.png 768w, https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2026\/02\/ben-flyswat-782x680.png 782w\" sizes=\"(max-width: 750px) 100vw, 750px\"><\/p>\n<p id=\"caption-attachment-73249\" class=\"wp-caption-text\">Dort and friends incriminating themselves by planning swatting attacks in a public Discord server.<\/p>\n<\/div>\n<p>Last week, Dort and friends used that same Discord server (then named \u201cKrebs\u2019s Koinbase Kallers\u201d) to threaten a swatting attack against Brundage, again posting his home address and personal information. Brundage told KrebsOnSecurity that local police officers subsequently visited his home in response to a swatting hoax which occurred around the same time that another member of the server posted a door emoji and taunted Brundage further.<\/p>\n<div id=\"attachment_73245\" style=\"width: 758px\" class=\"wp-caption aligncenter\">\n<img data-recalc-dims=\"1\" aria-describedby=\"caption-attachment-73245\" decoding=\"async\" loading=\"lazy\" class=\" wp-image-73245\" src=\"https:\/\/i0.wp.com\/krebsonsecurity.com\/wp-content\/uploads\/2026\/02\/ben-door.png?resize=748%2C155&#038;ssl=1\" alt=\"\" width=\"748\" height=\"155\"><\/p>\n<p id=\"caption-attachment-73245\" class=\"wp-caption-text\">Dort, using the alias \u201cMeow,\u201d taunts Synthient founder Ben Brundage with a picture of a door.<\/p>\n<\/div>\n<p>Someone on the server then linked to a cringeworthy (and NSFW) new Soundcloud <a href=\"https:\/\/soundcloud.com\/dortdev\/larpgod\" target=\"_blank\" rel=\"noopener\">diss track<\/a> recorded by the user DortDev that included a stickied message from Dort saying, \u201cUr dead nigga. u better watch ur fucking back. sleep with one eye open. bitch.\u201d<\/p>\n<p>\u201cIt\u2019s a pretty hefty penny for a new front door,\u201d the diss track intoned. \u201cIf his head doesn\u2019t get blown off by SWAT officers. What\u2019s it like not having a front door?\u201d<\/p>\n<p class=\"p1\">With any luck, Dort will soon be able to tell us all exactly what it\u2019s like.<\/p>\n<p><strong>Update, 10:29 a.m.:<\/strong> Jacob Butler responded to requests for comment, speaking with KrebsOnSecurity briefly via telephone. Butler said he didn\u2019t notice earlier requests for comment because he hasn\u2019t really been online since 2021, after his home was swatted multiple times. He acknowledged making and distributing a Minecraft cheat long ago, but said he hasn\u2019t played the game in years and was not involved in Dortsolver or any other activity attributed to the Dort nickname after 2021.<\/p>\n<p>\u201cIt was a really old cheat and I don\u2019t remember the name of it,\u201d Butler said of his Minecraft modification. \u201cI\u2019m very stressed, man. I don\u2019t know if people are going to swat me again or what. After that, I pretty much walked away from everything, logged off and said fuck that. I don\u2019t go online anymore. I don\u2019t know why people would still be going after me, to be completely honest.\u201d<\/p>\n<p>When asked what he does for a living, Butler said he mostly stays home and helps his mom around the house because he struggles with autism and social interaction. He maintains that someone must have compromised one or more of his old accounts and is impersonating him online as Dort.<\/p>\n<p>\u201cSomeone is actually probably impersonating me, and now I\u2019m really worried,\u201d Butler said. \u201cThis is making me relive everything.\u201d<\/p>\n<p>But there are issues with Butler\u2019s timeline. For example, Jacob\u2019s voice in our phone conversation was remarkably similar to the Jacob\/Dort whose voice can be heard in <a href=\"https:\/\/www.youtube.com\/watch?v=yntHEanT3u8\" target=\"_blank\" rel=\"noopener\">this Sept. 2022 Clash of Code competition<\/a> between Dort and another coder (Dort lost). At around 6 minutes and 10 seconds into the recording, Dort launches into a cursing tirade that mirrors the stream of profanity in the diss rap that Dortdev posted threatening Brundage. Dort can be heard again at around 16 minutes; at around 26:00, Dort threatens to swat his opponent.<\/p>\n<p>Butler said the voice of Dort is not his, exactly, but rather that of an impersonator who had likely cloned his voice.<\/p>\n<p>\u201cI would like to clarify that was absolutely not me,\u201d Butler said. \u201cThere must be someone using a voice changer. Or something of the sorts. Because people were cloning my voice before and sending audio clips of \u2018me\u2019 saying outrageous stuff.\u201d<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    BrianKrebs<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/krebsonsecurity.com\/2026\/02\/who-is-the-kimwolf-botmaster-dort\/\">Go to krebsonsecurity<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Who is the Kimwolf Botmaster \u201cDort\u201d? In early January 2026, KrebsOnSecurity revealed how a security researcher disclosed a vulnerability that was used to build Kimwolf, the world\u2019s largest and most disruptive botnet. Since then, the person in control of Kimwolf \u2014 who goes by the handle \u201cDort\u201d \u2014 has coordinated a barrage of distributed denial-of-service [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[188,368,709,2319,230,440,2210,2320,2321,2322,1319,899,320,2323,2324,2198,55,2325,428,190,2272,2326,2102],"tags":[72],"class_list":["post-11037","post","type-post","status-publish","format-standard","hentry","category-a-little-sunshine","category-breadcrumbs","category-constella-intelligence","category-cpacket","category-ddos-for-hire","category-domaintools","category-dort","category-dortdev","category-dortsolver","category-epieos","category-flashpoint","category-github","category-intel-471","category-jacobbutler803gmail-com","category-jay-miner232gmail-com","category-kimwolf-botnet","category-krebsonsecurity","category-m1ce","category-minecraft","category-neer-do-well-news","category-osint-industries","category-qoft","category-spycloud","tag-krebsonsecurity"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/11037"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=11037"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/11037\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=11037"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=11037"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=11037"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}