Satori Botnet Operator Pleaded Guilty to Computer Intrusions

The defendant admitted to orchestrating a botnet that compromised 100,000 IoT devices for denial-of-service attacks.

Updated on Sept. 26, 2026 in Cybersecurity

Bold flat-color editorial illustration showing an upright server rack in navy and cream, representing large-scale digital infrastructure.
Kenneth Currin Schuchman has pleaded guilty to operating the Satori botnet, which compromised 100,000 IoT devices to launch massive denial-of-service attacks. AI Illustration. Upload story photo >

Live Poll

Do you trust the security of internet-connected devices in your home?

Kenneth Currin Schuchman, 21, has pleaded guilty to aiding and abetting computer intrusions after operating the Satori IoT botnet. The conspiracy compromised approximately 100,000 routers, digital video recorders, and cameras to rent access for malicious traffic floods.

Why it matters

This case highlights the enduring vulnerability of the consumer Internet of Things (IoT) ecosystem, where unpatched devices are routinely weaponized for large-scale distributed denial-of-service (DDoS) attacks. It underscores the difficulty of securing decentralized, connected hardware against exploitation.

The Satori botnet compromised 100,000 devices by scanning the internet for specific vulnerabilities in routers and security cameras. The operation sought to rent this infrastructure for high-volume junk traffic, which can reach scales like the 620 Gbps demonstrated by Mirai-based attacks.

The players

Kenneth Currin Schuchman

A 21-year-old operator of the Satori IoT botnet who functioned under the aliases Nexus and Nexus-Zeta.

The details

Schuchman used the aliases Nexus and Nexus-Zeta to coordinate the botnet, which targeted devices by exploiting known vulnerabilities in their firmware. The software was engineered to automatically scan the internet for connected systems, then flood those devices with malicious commands to gain control. The conspirators then rented this access to third parties to execute denial-of-service attacks, a technique where a network is overwhelmed by an influx of data until it becomes unavailable to legitimate users. Even while under supervision in 2018, the defendant continued developing new variants of the botnet code.

Timeline

  1. Summer 2016: The Mirai botnet first appeared in the wild.

  2. July 2017 to October 2018: Schuchman conspired to develop and operate the Satori botnet.

  3. August 2018: Schuchman was indicted for his criminal activities.

  4. October 2018: Schuchman orchestrated a swatting attack against a co-conspirator.

  5. September 25, 2026: The guilty plea was formally reported.

The Tech Race

The development of Satori follows the architectural precedent established by the 2016 Mirai botnet attack. The case demonstrates how lightweight, modular botnet code continues to evolve and proliferate long after the initial discovery of its parent infrastructure.

Owners of older or unmanaged routers and security cameras remain the primary targets for this type of automated exploitation. Securing these devices requires manually applying firmware updates or replacing legacy hardware that no longer receives security patches from the manufacturer.

The takeaway

The case serves as a reminder that IoT security relies on the maintenance of peripheral devices that users often ignore after initial setup. Schuchman now faces a maximum penalty of 10 years in federal prison and $250,000 in fines as the case moves toward final sentencing.

Further reading

For more on evolving threats to connected infrastructure, visit Cybersecurity.

Source note: This article includes information reported by Briankrebs.

Live Poll

Do you trust the security of internet-connected devices in your home?