The College Student Who Defeated the World’s Biggest Cyberweapon

The College Student Who Defeated the World’s Biggest Cyberweapon

A 22-year-old college student cracked the world's biggest botnet from his dorm room using a cat meme, an old Android phone, and a DIY honeypot — then got thanked by the DOJ.

May 1, 2026 37:24 Difficulty: Intermediate Played

TL;DR

A 22-year-old college senior named Benjamin Brundage stumbled onto KimWolf — the largest botnet ever observed — while researching shady residential proxy networks from his dorm room. Using Discord cat memes, a DIY honeypot Android phone, and 2 million cataloged IP addresses, Ben cracked the mystery that stumped professional cybersecurity teams. His findings helped Google, the DOJ, and a working group called Big Pipes dismantle a network behind 26,000+ DDoS attacks. The key takeaway: the internet has an "internet pollution" problem, filled with compromised consumer devices few know how to fix.

#KimWolf botnet #DDoS attacks #residential proxy networks #IP address hijacking #internet pollution #IoT security #ethical hacking #bug bounty #Big Pipes working group #DOJ cybercrime enforcement #Google court action #college student cybersecurity #KimWolf #botnet #DDoS attack #Benjamin Brundage #residential proxy #IP Idea #cybersecurity #Big Pipes #internet security #IoT devices #hacking #Department of Justice #Google #Lumen #Synthient

WSJ reporter Robert McMillan investigates KimWolf, the largest botnet ever observed, and how 22-year-old college student Benjamin Brundage played a critical role in unraveling and helping dismantle it.

Chapter list
  • The episode opens with a striking framing device: the people who defend the internet are 'wizards,' and over the last year those wizards faced something unlike anything they had ever encountered. WSJ cybersecurity reporter Robert McMillan introduces KimWolf, a fast-growing botnet that quietly hijacked nearly 2 million Android and consumer devices — phones, cameras, TV boxes, picture frames — and turned them into a single, devastating cyberweapon. McMillan explains what DDoS attacks are: armies of computers flooding a target with junk data until it collapses. KimWolf was doing this at an unprecedented scale, and the wizards' greatest fear was stark: the internet itself could be knocked out. Against this backdrop, Jessica Mendoza teases the episode's hero — a 22-year-old college senior named Benjamin Brundage who would help crack the case from his dorm room.

  • A brief sponsored segment from Accenture promotes its partnership with Spotify to automate advertising operations, promising smarter workflows, better data access, and more time for teams to focus on connecting brands with audiences. Listeners are directed to accenture.com/spotify for more information.

  • Tremfya is advertised as a prescription medicine for adults suffering from moderately to severely active Crohn's disease or ulcerative colitis, offering both self-injection and intravenous infusion options. The segment includes full safety disclosures, including risks of serious allergic reactions, infections, and liver problems, and directs listeners to consult their doctors.

  • Long before he was fighting the world's biggest botnet, Ben Brundage was just a kid who liked hiking and skiing. That changed in 2020 when COVID lockdowns drove him to Minecraft, and the game's modding system sparked a genuine love of code. Ben learned Java by watching late-night tutorials, built custom plants and creatures, and then discovered the darker side: cheats that let him see through walls and auto-aim at enemies, eventually getting his account banned. On Discord, Minecraft modding communities blurred almost imperceptibly into hacker forums — servers on cybercrime were just a few hops away. Ben recounts how easy it was to get drawn in, describing the normalization that happens when you spend enough time around people who treat cybercrime as routine. His moral alarm bells finally rang when he stumbled on a list of 100 stolen Spotify Premium accounts posted openly in a server — rather than join in, he emailed all 60-some account holders to warn them, a decision that set the direction of his life.

  • Recognizing that the road he was on with hacking communities wasn't going to end well, Ben Brundage made a deliberate pivot toward cybersecurity. His first real test came in his senior year of high school, when the Dutch government opened an invitation to hackers worldwide to find vulnerabilities in its websites. Ben submitted not one but two major bugs. The reward was a black t-shirt emblazoned with 'Hacked the Dutch government, and all I got was this lousy t-shirt' — a joke prize that nonetheless gave Ben a genuine rush. He carried that energy into Rochester Institute of Technology, where he studied computer science and taught himself to automate tasks and build bots. That skill set, assembled without any awareness of what was coming, was about to point him directly at KimWolf.

  • Every device on the internet has an IP address — essentially a phone number — that websites use to identify who's visiting. Residential proxy networks exploit that by letting third parties route their traffic through someone else's home IP, making the traffic look like it comes from an ordinary household. McMillan uses the Airbnb analogy: you might be unknowingly renting out your internet address. Some residential proxy companies obtain these IPs legitimately; others do not. The shadiest ones sneak malware onto devices through pirated streaming apps or sell cheap internet-connected gadgets — TV boxes, picture frames — with proxy software pre-installed. The criminal applications are extensive: covering the tracks of nation-state hackers, helping ticket scalpers buy in bulk, enabling identity fraud. Ben, still a college student, found himself fascinated by this obscure corner of the internet, sensing that something bigger was hiding beneath it.

  • By August of last year, Ben had turned his hobby research into a one-man company — Synthient — and was building a comprehensive database of suspicious residential proxy IP addresses. Browsing the landscape of res proxy providers, he noticed something that didn't add up: the websites were eerily identical. Same checkout flow, same user interface, just different branding and color schemes. Digging deeper, he traced all of them back to a single entity: IP Idea. The company was enigmatic — no CEO listed, no founder, no address, more than a dozen operating brands. What especially stood out was what it lacked: the guardrails most proxy companies have to prevent their networks from being used for fraud. IP Idea had none. Ben published an online tool on Discord that let users check whether their IP was in his database — and that's when a mysterious message arrived.

  • A week after Ben posted his IP-address tool on Discord, a message arrived from an unknown user who said, in effect, 'Nice try — you missed some.' The user attached screenshots proving it. Ben could tell from their typing style — the casual abbreviations, the GIFs, the emoji use — that this was probably someone close to his own age, not a seasoned criminal. Rather than confronting them, Ben played it cool, responding with a GIF of a cat in a tuxedo to signal he wasn't a threat. It worked. The hacker opened up, revealing they had a 'novel exploit' for gaining access to devices, that they were running a botnet-for-hire service, and — most alarmingly — that the operation was spending $30,000 a month on infrastructure, was 'not some rinky-dink operation,' and came with an explicit message: don't investigate us. For Ben, those three data points lit up like red flags, confirming that something far larger was going on.

  • The thing Ben had stumbled into wasn't just a botnet — it was KimWolf, the most extreme botnet operation ever observed. A single attack had traffic equivalent to every person in Germany, Spain, and the United Kingdom hitting the same website at the exact same second. Cybersecurity professionals had been tracking it for months. Chris Formosa, an engineer at the networking company Lumen, had been focusing his research on IP Idea specifically, watching the botnet grow at an unchecked pace. But the central mystery remained unsolved: nobody knew how KimWolf was getting its victims. The worry was that the network had millions of IP addresses and no one checking what was happening on it — a situation ripe for catastrophic abuse.

  • When a mutual contact told Chris Formosa there was someone he needed to meet, he didn't expect a 22-year-old college student. But from the moment they connected, the collaboration was electric: their first conversation lasted 8 hours, with notes flying back and forth between them. Ben shared what he'd learned about IP Idea and the details he'd extracted from his Discord conversations with the anonymous hacker. Chris quickly realized Ben's Discord contact was likely connected to KimWolf itself. Shortly after, Chris introduced Ben to Big Pipes — a secretive working group of engineers from major internet companies, the 'wizards' who monitor the actual flows of data across the internet's backbone. Ben joined their weekly conference calls, a college student suddenly sitting at the same table as the people running the infrastructure of the internet.

  • For months, Big Pipes had been watching KimWolf's attacks but couldn't figure out how the hackers were enrolling devices. Then one of their own members noticed something alarming: their own IP address was being used in an attack. They asked the employee to investigate their home network. The culprit turned out to be a $50 digital picture frame — the kind you update with photos from your phone. This cheap, seemingly harmless device had been secretly conscripted into KimWolf's army. With an actual piece of infected hardware in hand for the first time, Big Pipes had a concrete object to tear apart and study. Now the question was: how exactly was KimWolf getting in? That answer would have to come from Ben.

  • A brief sponsored segment from Intuit promotes the Intuit Enterprise Suite, described as a powerful, painless, and proven AI-native ERP solution for finance teams dealing with fragmented data sources and the challenges of business scaling.

  • Ben's big insight was simple but brilliant: if you want to catch something exploiting residential proxy devices, become one. He installed IP Idea's software on a spare Android phone, downloaded from a website offering pirated streaming content, and built a monitoring setup to capture every byte of traffic coming in and out. Then he waited — balancing the experiment with studying for midterms. Within a week, one domain kept appearing in the traffic logs: xd.resi.to, an address with no obvious connection to IP Idea. Ben immediately flagged it. The domain turned out to be KimWolf's foothold: it was using the residential proxy's own access to the device to pivot from the open internet into the phone's local network — and from there, commandeer the device entirely. As Robert McMillan put it, it was like an Airbnb guest deciding to squat in the rental and rummage through all the locked closets. Ben brought his findings to Big Pipes, and together they confirmed that KimWolf had exploited a bug in IP Idea's own code to pull off this attack at scale.

  • With the exploit understood, Ben moved to warn the industry. He identified 10 other residential proxy companies vulnerable to the same bug IP Idea had. As his final exams loomed, he drafted notifications to all of them, sending the emails on December 17th — the day after his last test. IP Idea replied 9 days later, claiming the email had gone to spam and promising a fix. It was too little, too late. In January, Google obtained a US court order and moved decisively: 13 of IP Idea's business domains were taken down and dozens of its servers were shut off. Google had by then identified over 10 million devices pre-installed with IP Idea's software. Two months later, in March, the Department of Justice struck against four of the world's largest DDoS botnets, including KimWolf — seizing domains, virtual servers, and network infrastructure. At the end of the DOJ press release was a list of companies thanked for their help. Among the major tech firms was Synthient: Ben's one-man startup, operating out of a college dorm room.

  • Despite the Google and DOJ actions, KimWolf hasn't been fully exterminated — it still lurks in thousands of compromised devices, a reminder that botnets are stubbornly resilient. Robert McMillan frames the lasting lesson with characteristic bluntness: the internet is full of junk. Garbage devices and garbage apps have quietly become part of the criminal infrastructure, and the problem — what he calls 'internet pollution' — has no clear solution yet. For listeners who want to know if their own network is secretly enrolled in a residential proxy, Bob has written a guide available in the show notes. As for Ben Brundage, the unlikely hero of the whole story, he's now focused on finishing his degree, growing Synthient, and maybe taking his first real vacation in a long time. And if the rumors he's heard are true, there might be a t-shirt in his future — one that says, 'I stopped KimWolf, and all I got was this lousy t-shirt.'

DDoS attack
Distributed Denial-of-Service attack: flooding a server with so much junk traffic from many computers simultaneously that it becomes overwhelmed and stops functioning.
Botnet
A network of computers or internet-connected devices that have been secretly compromised and are controlled remotely, typically to carry out coordinated cyberattacks.
Residential proxy
A service that routes internet traffic through real home users' IP addresses, making the traffic appear to originate from a legitimate household rather than a server.
IP address
Internet Protocol address: a unique numerical label assigned to every device on a network, functioning like a phone number that identifies where internet traffic comes from and goes to.
Honeypot
A cybersecurity trap — a decoy device or system deliberately left vulnerable to attract attackers and study their methods without exposing real assets.
Reverse engineering
The process of analyzing software or hardware to understand how it works internally, often to find vulnerabilities or replicate functionality.
Exploit
A piece of code or technique that takes advantage of a software vulnerability to gain unauthorized access or perform unintended actions on a system.
Blacklisted
In cybersecurity, when an IP address or domain is added to a list of known bad actors and subsequently blocked by websites and services across the internet.
Local network
The private network within a home or office connecting devices like phones, computers, and smart appliances — distinct from the open internet.
Cybercrime as a service
A business model where criminal hackers sell access to their malicious tools or infrastructure (like botnets) to other criminals for a fee, lowering the barrier to conducting cyberattacks.
Bug bounty
A program offered by organizations inviting ethical hackers to find and report security vulnerabilities in exchange for a reward, ranging from cash to merchandise.
Infrastructure (cyber context)
The servers, domains, and network systems that support the operation of an online service or, in criminal contexts, a cyberattack operation.
Malware
Malicious software designed to damage, disrupt, or gain unauthorized access to a computer system or device.
Egregious
Outstandingly bad or shocking; used here by Benjamin Brundage to describe his reaction to seeing hundreds of stolen Spotify account credentials shared openly online.
Piqued (curiosity)
Stimulated or aroused, especially interest or curiosity; used to describe how IP Idea's lack of security measures caught Benjamin Brundage's attention.

Chapter 1 · 00:00

Intro: The Wizards of the Internet Face Their Biggest Threat

The episode opens with a striking framing device: the people who defend the internet are 'wizards,' and over the last year those wizards faced something unlike anything they had ever encountered. WSJ cybersecurity reporter Robert McMillan introduces KimWolf, a fast-growing botnet that quietly hijacked nearly 2 million Android and consumer devices — phones, cameras, TV boxes, picture frames — and turned them into a single, devastating cyberweapon. McMillan explains what DDoS attacks are: armies of computers flooding a target with junk data until it collapses. KimWolf was doing this at an unprecedented scale, and the wizards' greatest fear was stark: the internet itself could be knocked out. Against this backdrop, Jessica Mendoza teases the episode's hero — a 22-year-old college senior named Benjamin Brundage who would help crack the case from his dorm room.

Chapter 4 · 04:43

Ben's Origin Story: Minecraft, Cheating, and the Gateway to Hacking

Long before he was fighting the world's biggest botnet, Ben Brundage was just a kid who liked hiking and skiing. That changed in 2020 when COVID lockdowns drove him to Minecraft, and the game's modding system sparked a genuine love of code. Ben learned Java by watching late-night tutorials, built custom plants and creatures, and then discovered the darker side: cheats that let him see through walls and auto-aim at enemies, eventually getting his account banned. On Discord, Minecraft modding communities blurred almost imperceptibly into hacker forums — servers on cybercrime were just a few hops away. Ben recounts how easy it was to get drawn in, describing the normalization that happens when you spend enough time around people who treat cybercrime as routine. His moral alarm bells finally rang when he stumbled on a list of 100 stolen Spotify Premium accounts posted openly in a server — rather than join in, he emailed all 60-some account holders to warn them, a decision that set the direction of his life.

Chapter 5 · 10:20

Choosing the Right Side: Bug Bounties and the Path to Cybersecurity

Recognizing that the road he was on with hacking communities wasn't going to end well, Ben Brundage made a deliberate pivot toward cybersecurity. His first real test came in his senior year of high school, when the Dutch government opened an invitation to hackers worldwide to find vulnerabilities in its websites. Ben submitted not one but two major bugs. The reward was a black t-shirt emblazoned with 'Hacked the Dutch government, and all I got was this lousy t-shirt' — a joke prize that nonetheless gave Ben a genuine rush. He carried that energy into Rochester Institute of Technology, where he studied computer science and taught himself to automate tasks and build bots. That skill set, assembled without any awareness of what was coming, was about to point him directly at KimWolf.

Chapter 6 · 12:40

Residential Proxies: The Internet's Grey Market for IP Addresses

Every device on the internet has an IP address — essentially a phone number — that websites use to identify who's visiting. Residential proxy networks exploit that by letting third parties route their traffic through someone else's home IP, making the traffic look like it comes from an ordinary household. McMillan uses the Airbnb analogy: you might be unknowingly renting out your internet address. Some residential proxy companies obtain these IPs legitimately; others do not. The shadiest ones sneak malware onto devices through pirated streaming apps or sell cheap internet-connected gadgets — TV boxes, picture frames — with proxy software pre-installed. The criminal applications are extensive: covering the tracks of nation-state hackers, helping ticket scalpers buy in bulk, enabling identity fraud. Ben, still a college student, found himself fascinated by this obscure corner of the internet, sensing that something bigger was hiding beneath it.

Chapter 7 · 15:20

Ben Discovers IP Idea and Its Cookie-Cutter Empire

By August of last year, Ben had turned his hobby research into a one-man company — Synthient — and was building a comprehensive database of suspicious residential proxy IP addresses. Browsing the landscape of res proxy providers, he noticed something that didn't add up: the websites were eerily identical. Same checkout flow, same user interface, just different branding and color schemes. Digging deeper, he traced all of them back to a single entity: IP Idea. The company was enigmatic — no CEO listed, no founder, no address, more than a dozen operating brands. What especially stood out was what it lacked: the guardrails most proxy companies have to prevent their networks from being used for fraud. IP Idea had none. Ben published an online tool on Discord that let users check whether their IP was in his database — and that's when a mysterious message arrived.

Chapter 8 · 18:30

The Hacker Makes Contact: A Cat Meme and $30K a Month

A week after Ben posted his IP-address tool on Discord, a message arrived from an unknown user who said, in effect, 'Nice try — you missed some.' The user attached screenshots proving it. Ben could tell from their typing style — the casual abbreviations, the GIFs, the emoji use — that this was probably someone close to his own age, not a seasoned criminal. Rather than confronting them, Ben played it cool, responding with a GIF of a cat in a tuxedo to signal he wasn't a threat. It worked. The hacker opened up, revealing they had a 'novel exploit' for gaining access to devices, that they were running a botnet-for-hire service, and — most alarmingly — that the operation was spending $30,000 a month on infrastructure, was 'not some rinky-dink operation,' and came with an explicit message: don't investigate us. For Ben, those three data points lit up like red flags, confirming that something far larger was going on.

Chapter 9 · 21:00

KimWolf's Scale: The Biggest Botnet Ever Seen

The thing Ben had stumbled into wasn't just a botnet — it was KimWolf, the most extreme botnet operation ever observed. A single attack had traffic equivalent to every person in Germany, Spain, and the United Kingdom hitting the same website at the exact same second. Cybersecurity professionals had been tracking it for months. Chris Formosa, an engineer at the networking company Lumen, had been focusing his research on IP Idea specifically, watching the botnet grow at an unchecked pace. But the central mystery remained unsolved: nobody knew how KimWolf was getting its victims. The worry was that the network had millions of IP addresses and no one checking what was happening on it — a situation ripe for catastrophic abuse.

Chapter 10 · 23:00

Ben Meets Chris Formosa and Joins Big Pipes

When a mutual contact told Chris Formosa there was someone he needed to meet, he didn't expect a 22-year-old college student. But from the moment they connected, the collaboration was electric: their first conversation lasted 8 hours, with notes flying back and forth between them. Ben shared what he'd learned about IP Idea and the details he'd extracted from his Discord conversations with the anonymous hacker. Chris quickly realized Ben's Discord contact was likely connected to KimWolf itself. Shortly after, Chris introduced Ben to Big Pipes — a secretive working group of engineers from major internet companies, the 'wizards' who monitor the actual flows of data across the internet's backbone. Ben joined their weekly conference calls, a college student suddenly sitting at the same table as the people running the infrastructure of the internet.

Chapter 11 · 24:08

The $50 Picture Frame That Cracked the Case

For months, Big Pipes had been watching KimWolf's attacks but couldn't figure out how the hackers were enrolling devices. Then one of their own members noticed something alarming: their own IP address was being used in an attack. They asked the employee to investigate their home network. The culprit turned out to be a $50 digital picture frame — the kind you update with photos from your phone. This cheap, seemingly harmless device had been secretly conscripted into KimWolf's army. With an actual piece of infected hardware in hand for the first time, Big Pipes had a concrete object to tear apart and study. Now the question was: how exactly was KimWolf getting in? That answer would have to come from Ben.

Chapter 12 · 26:30

Ad Break: Intuit Enterprise Suite

A brief sponsored segment from Intuit promotes the Intuit Enterprise Suite, described as a powerful, painless, and proven AI-native ERP solution for finance teams dealing with fragmented data sources and the challenges of business scaling.

Chapter 13 · 26:38

Ben's Honeypot: The DIY Trap That Exposed KimWolf's Exploit

Ben's big insight was simple but brilliant: if you want to catch something exploiting residential proxy devices, become one. He installed IP Idea's software on a spare Android phone, downloaded from a website offering pirated streaming content, and built a monitoring setup to capture every byte of traffic coming in and out. Then he waited — balancing the experiment with studying for midterms. Within a week, one domain kept appearing in the traffic logs: xd.resi.to, an address with no obvious connection to IP Idea. Ben immediately flagged it. The domain turned out to be KimWolf's foothold: it was using the residential proxy's own access to the device to pivot from the open internet into the phone's local network — and from there, commandeer the device entirely. As Robert McMillan put it, it was like an Airbnb guest deciding to squat in the rental and rummage through all the locked closets. Ben brought his findings to Big Pipes, and together they confirmed that KimWolf had exploited a bug in IP Idea's own code to pull off this attack at scale.

Chapter 14 · 30:55

The Takedown: Ben Warns the World, Google and DOJ Act

With the exploit understood, Ben moved to warn the industry. He identified 10 other residential proxy companies vulnerable to the same bug IP Idea had. As his final exams loomed, he drafted notifications to all of them, sending the emails on December 17th — the day after his last test. IP Idea replied 9 days later, claiming the email had gone to spam and promising a fix. It was too little, too late. In January, Google obtained a US court order and moved decisively: 13 of IP Idea's business domains were taken down and dozens of its servers were shut off. Google had by then identified over 10 million devices pre-installed with IP Idea's software. Two months later, in March, the Department of Justice struck against four of the world's largest DDoS botnets, including KimWolf — seizing domains, virtual servers, and network infrastructure. At the end of the DOJ press release was a list of companies thanked for their help. Among the major tech firms was Synthient: Ben's one-man startup, operating out of a college dorm room.

Chapter 15 · 34:25

The Aftermath: Internet Pollution and What Comes Next

Despite the Google and DOJ actions, KimWolf hasn't been fully exterminated — it still lurks in thousands of compromised devices, a reminder that botnets are stubbornly resilient. Robert McMillan frames the lasting lesson with characteristic bluntness: the internet is full of junk. Garbage devices and garbage apps have quietly become part of the criminal infrastructure, and the problem — what he calls 'internet pollution' — has no clear solution yet. For listeners who want to know if their own network is secretly enrolled in a residential proxy, Bob has written a guide available in the show notes. As for Ben Brundage, the unlikely hero of the whole story, he's now focused on finishing his degree, growing Synthient, and maybe taking his first real vacation in a long time. And if the rumors he's heard are true, there might be a t-shirt in his future — one that says, 'I stopped KimWolf, and all I got was this lousy t-shirt.'

No indexed bits in this chapter.

Show stoppers

Snapshots ()

Key Quotes ()

This episode

Claims & Sources

2 / 12 cited (17%)

Factual claims made this episode, and whether a source was named.

KimWolf quietly hijacked nearly 2 million Android devices across the globe.

Jessica Mendoza no source cited

KimWolf launched more than 26,000 DDoS attacks targeting over 8,000 victims, according to DOJ court filings.

Jessica Mendoza DOJ court filings

Google identified more than 10 million devices that came with IP Idea's software secretly pre-installed.

Jessica Mendoza no source cited

The KimWolf hacker told Benjamin Brundage that the operation was spending $30,000 a month on infrastructure.

Benjamin Brundage no source cited

One KimWolf DDoS attack was so large it was as if everyone in Germany, Spain, and the UK had visited the same website at the exact same second.

Jessica Mendoza no source cited

In January, Google used a US court order to take down 13 of IP Idea's business domains and shut down dozens of its servers.

Jessica Mendoza no source cited

The Department of Justice took action against four of the world's largest DDoS botnets, including KimWolf, by seizing internet domains, virtual servers, and other network infrastructure.

Jessica Mendoza no source cited

IP Idea appeared to operate under more than a dozen different brand names and listed no CEO, founder, or address on its websites.

Jessica Mendoza no source cited

Ben Brundage found two major security vulnerabilities in Dutch government websites during a public bug-bounty program while still in high school.

Benjamin Brundage no source cited

Ben Brundage identified around 2 million devices — including TV boxes, phones, cameras, and picture frames — that had been hacked by KimWolf.

Jessica Mendoza no source cited

IP Idea's fix to the exploited bug came too late: the company replied to Ben's notification 9 days after it was sent, claiming his email went to spam.

Jessica Mendoza no source cited

The DOJ's press release on the KimWolf takedown thanked Google, Lumen, and Synthient by name for their contributions.

Jessica Mendoza DOJ press release

This episode

Cast

  • Track
  • Track

Stats

Episode stats

Insight Overview

insights
chapters

Insight distribution

Sub-Categories

Speaker breakdown

Talk Time