---
title: "The Satori botnet’s operator pleads guilty — and he was not even the clever one"
description: "Kenneth Schuchman, 21, helped run an army of hacked gadgets under aliases that led straight back to his own name"
author: "Albion Grey"
published: 2026-09-26T00:42:16.936Z
modified: 2026-09-26T23:04:28Z
url: https://rews.cc/a/the-satori-botnet-s-operator-pleads-guilty-and-he-was-not-ev-0b4f8c
language: en
tags: ["cybersecurity", "botnet", "iot", "mirai", "hacking", "tech"]
publisher: "Rews (https://rews.cc)"
---

# The Satori botnet’s operator pleads guilty — and he was not even the clever one

*Kenneth Schuchman, 21, helped run an army of hacked gadgets under aliases that led straight back to his own name*

By Albion Grey · September 26, 2026 · https://rews.cc/a/the-satori-botnet-s-operator-pleads-guilty-and-he-was-not-ev-0b4f8c

## In brief

- Kenneth Currin Schuchman, 21, of Vancouver, Washington, pleaded guilty to aiding and abetting computer intrusions
- The Satori botnet harnessed about 100,000 hacked IoT devices to attack providers, gaming and hosting firms
- Rebranded variants called Okiru and Masuta infected up to 700,000 systems and were built to be rented out
- Indicted in August 2018, Schuchman built a new variant while on supervised release and arranged a “swatting”
- The maximum sentence is 10 years and a $250,000 fine, but the plea deal recommends the low end of the range

Most cybercriminals shelter behind menacing pseudonyms. Kenneth Currin Schuchman chose two — “Nexus” and “Nexus-Zeta” — and then registered his botnet’s command server under a Gmail address, nexuczeta1337@gmail.com, that pointed back to a “Kenny Schuchman” of Vancouver, Washington. Mr Schuchman, 21, has now pleaded guilty to one federal count of aiding and abetting computer intrusions, admitting his role in Satori, a botnet assembled from hacked internet-of-things (IoT) devices.

According to his plea agreement, between July 2017 and October 2018 Mr Schuchman conspired with at least two others, known online as “Vamp” and “Drake”, to build and deploy Satori in large-scale denial-of-service attacks: floods of junk traffic that left targets unreachable by legitimate visitors. The marks were internet service providers, online gaming platforms and web-hosting companies. The weapon was the pooled bandwidth of about 100,000 hacked devices, enslaved through vulnerabilities in wireless routers, digital video recorders, internet-connected security cameras and fibre-optic networking gear.

## Mirai’s unruly children

Satori began life as a remix of the leaked source code for Mirai, the IoT botnet that appeared in the summer of 2016 and carried out some of the largest denial-of-service attacks ever recorded — including a 620-gigabits-per-second assault that took the KrebsOnSecurity blog offline for almost four days. Through 2017 and into 2018 Mr Schuchman and his partners kept finding and exploiting fresh flaws in other IoT systems, rechristening their creations “Okiru” and “Masuta” with almost every improvement. At their height the variants infected up to 700,000 compromised systems.

The object of the conspiracy, the plea agreement states, was to sell access to the botnets to others wishing to rent them for attacks — though how far the trio succeeded is unclear. Mr Schuchman’s conduct after his indictment in August 2018 was not that of a chastened man. While on supervised release he built a new botnet variant. He also fell out with Drake, and later acknowledged using information gleaned by prosecutors to identify his erstwhile partner’s home address.

That was the prelude to a “swatting”: a false report of violent mayhem — a hostage situation, a bomb threat, a murder — designed to send a heavily armed police response to a victim’s door. The call Mr Schuchman set in motion in October 2018 produced “a substantial law enforcement response at Drake’s residence”, according to the plea agreement.

The tradecraft elsewhere was no better. Beyond the telltale domain — originally registered to a “ZetaSec Inc.” as well as to Mr Schuchman himself — the constant scanning that keeps such botnets fed with new victims drew abuse complaints from internet providers. Mr Schuchman answered them in his father’s identity. The plea agreement states it flatly:

> Schuchman frequently used identification devices belonging to his father to further the criminal scheme.

## The brains, it seems, were elsewhere

Mr Schuchman may be the first person to plead guilty over Satori and its progeny, but those familiar with the case rank him low among its villains. Multiple sources tell KrebsOnSecurity that Vamp is a British resident who was principally responsible for coding Satori, and that as a minor he was involved in the 2015 hack of TalkTalk, a British phone and broadband provider. The same sources say Vamp was principally responsible for the enormous 2016 attack on Dyn, a firm providing core internet services for big-name websites, which on October 21st that year caused outages at Twitter, Spotify, Reddit and others.

The investigation is being run out of the Federal Bureau of Investigation’s field office in Alaska, spearheaded by some of the same agents who helped track down the original co-authors of Mirai and secure their guilty pleas. For Mr Schuchman — reportedly diagnosed with Asperger syndrome and autism — the single count carries a maximum of 10 years in prison and fines of up to $250,000. His plea deal points somewhere much softer: he agreed to a recommended sentence “at the low end of the guideline range as calculated and adopted by the court.”

Botnet cases have a habit of ending this way: the careless sign-up in the dock, the true author still a nickname in a chat log. The real defendants, meanwhile — millions of unpatched routers and cameras — remain at large, waiting for the next Mirai to recruit them.
