Alleged Kimwolf Botmaster ‘Dort’ Arrested, Charged in U.S. and Canada
2026-05-22T07:23:28Z•57d5ac8b4ded9c7132b63bf0bfae896ab306f9d3b202739f2c80ae10f09dadf5
AWS GovCloudAdobe ReaderBlueHammerCISACanisterWormCanvasChrome zero-dayDDoSGandCrabGitHub leakIoT botnetKimwolfMicrosoft Office token theftREvilScattered Spider','phishing','doxing','swattinganti-DDoS abusearrestcredential leakdata extortioneducation breachpatch Tuesdayrouter compromisestate-backed actorswiperzero-day
What happened
Collection of KrebsOnSecurity reports (Mar–May 2026) detailing multiple high-impact cyber incidents: arrest of an alleged Kimwolf IoT botnet operator tied to large-scale DDoS, doxing and swatting campaigns; a public GitHub leak by a CISA contractor exposing privileged AWS GovCloud keys and internal build/deploy artifacts; widespread patching activity (Apr–May Patch Tuesday) addressing numerous vulnerabilities including Windows/SharePoint, Chrome and Adobe Reader zero-days and the ‘BlueHammer’ issue; a large-scale data extortion and service disruption of education platform Canvas affecting ~275
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- krebs_on_security
- Record identifier
- 57d5ac8b4ded9c7132b63bf0bfae896ab306f9d3b202739f2c80ae10f09dadf5
- Enrichment time
- 2026-05-22T07:23:28Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.