Dort Kimwolf retaliatory harassment campaign
Campaign
Summary
Hide ▲
Show ▼
The Dort-controlled Kimwolf operation escalated into a targeted harassment campaign against the researcher and the author, combining DDoS, doxing, and email flooding. The campaign later escalated to swatting, creating an immediate physical-safety risk at the researcher’s home. The activity has continued since early January 2026, showing coordinated follow-on abuse tied to the botnet operator.
Related Happenings
Dort-linked DDoS, doxing, and swatting campaign against researchers
Campaign
H score38
First: 22.05.2026 00:50
Last: 22.05.2026 00:50
Sources 1
About this happening:
The Dort-linked harassment campaign targeted this author and a security researcher, using DDoS, doxing, and swatting to intimidate the people investigating the operato...
Dort-linked DDoS, doxing, and swatting campaign against researchers
CampaignAbout this happening: The Dort-linked harassment campaign targeted this author and a security researcher, using DDoS, doxing, and swatting to intimidate the people investigating the operato...
NCA National Strategic Assessment launch and teen cybercrime warning
Public Sector Action
H score26
First: 20.03.2026 11:40
Last: 20.03.2026 11:40
Sources 1
About this happening:
The UK National Crime Agency (NCA) launched its National Strategic Assessment and warned that online platforms are helping draw teens into cybercrime. Director gen...
NCA National Strategic Assessment launch and teen cybercrime warning
Public Sector ActionAbout this happening: The UK National Crime Agency (NCA) launched its National Strategic Assessment and warned that online platforms are helping draw teens into cybercrime. Director gen...
OFAC sanctions DPRK IT worker scheme network
Regulatory/Legal Action
H score32
First: 18.03.2026 19:26
Last: 18.03.2026 19:26
Sources 1
About this happening:
OFAC sanctioned Ryujong Credit Bank, KMCTC, and eight individuals tied to North Korean cryptocurrency laundering and fraudulent IT worker schemes. The U....
OFAC sanctions DPRK IT worker scheme network
Regulatory/Legal ActionAbout this happening: OFAC sanctioned Ryujong Credit Bank, KMCTC, and eight individuals tied to North Korean cryptocurrency laundering and fraudulent IT worker schemes. The U....
MuddyWater U.S. network intrusion campaign targeting banks, airports, and a software company arm
Campaign
H score42
First: 06.03.2026 12:23
Last: 06.03.2026 12:23
Sources 1
About this happening:
MuddyWater (Seedworm) is running a state-linked intrusion campaign that has embedded itself in U.S. banks, airports, a non-profit, and an Israeli software company arm,...
MuddyWater U.S. network intrusion campaign targeting banks, airports, and a software company arm
CampaignAbout this happening: MuddyWater (Seedworm) is running a state-linked intrusion campaign that has embedded itself in U.S. banks, airports, a non-profit, and an Israeli software company arm,...
Middle East retaliatory hacktivist DDoS campaign
Campaign
H score29
First: 04.03.2026 19:21
Last: 04.03.2026 19:21
Sources 1
About this happening:
A retaliatory hacktivist DDoS campaign has surged across the Middle East, creating broad disruption risk for government and public-infrastructure targets. Research...
Middle East retaliatory hacktivist DDoS campaign
CampaignAbout this happening: A retaliatory hacktivist DDoS campaign has surged across the Middle East, creating broad disruption risk for government and public-infrastructure targets. Research...
Timeline
-
28.02.2026 14:01 2 articles · 4mo ago
Dort launches Discord retaliation after the Kimwolf disclosure
Campaign Scope UpdateWithin hours of the January 2, 2026 disclosure about Kimwolf's residential proxy weakness, Dort created a Discord server in the author's name and began publishing personal information and violent threats against Benjamin Brundage, the researcher, the author, and others.
Show sources
- Who is the Kimwolf Botmaster “Dort”? — krebsonsecurity.com — 28.02.2026 14:01
- Who is the Kimwolf Botmaster “Dort”? — krebsonsecurity.com — 28.02.2026 14:01