Alleged Kimwolf Botmaster ‘Dort’ Arrested, Charged in U.S. and Canada

2026-05-22T07:23:28Z57d5ac8b4ded9c7132b63bf0bfae896ab306f9d3b202739f2c80ae10f09dadf5
AWS GovCloudAdobe ReaderBlueHammerCISACanisterWormCanvasChrome zero-dayDDoSGandCrabGitHub leakIoT botnetKimwolfMicrosoft Office token theftREvilScattered Spider','phishing','doxing','swattinganti-DDoS abusearrestcredential leakdata extortioneducation breachpatch Tuesdayrouter compromisestate-backed actorswiperzero-day

What happened

Collection of KrebsOnSecurity reports (Mar–May 2026) detailing multiple high-impact cyber incidents: arrest of an alleged Kimwolf IoT botnet operator tied to large-scale DDoS, doxing and swatting campaigns; a public GitHub leak by a CISA contractor exposing privileged AWS GovCloud keys and internal build/deploy artifacts; widespread patching activity (Apr–May Patch Tuesday) addressing numerous vulnerabilities including Windows/SharePoint, Chrome and Adobe Reader zero-days and the ‘BlueHammer’ issue; a large-scale data extortion and service disruption of education platform Canvas affecting ~275

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
krebs_on_security
Record identifier
57d5ac8b4ded9c7132b63bf0bfae896ab306f9d3b202739f2c80ae10f09dadf5
Enrichment time
2026-05-22T07:23:28Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.