Satori Botnet Operator Pleaded Guilty to Computer Intrusions
Kenneth Currin Schuchman admitted to operating a botnet that compromised 100,000 internet-connected devices.
Updated on Sept. 26, 2026 in Cybersecurity

Live Poll
Do you trust the security of internet-connected devices in your home?
Kenneth Currin Schuchman, known by the aliases Nexus and Nexus-Zeta, pleaded guilty to aiding and abetting computer intrusions. He operated the Satori IoT botnet, which targeted vulnerabilities in routers and security cameras to launch denial-of-service attacks.
Why it matters
The case highlights the significant threat posed by botnets that exploit the growing number of insecure, internet-connected home devices. By selling access to these compromised networks, operators can facilitate widespread online disruption.
The Satori botnet compromised approximately 100,000 IoT devices, including digital video recorders and routers. The defendant faces a maximum penalty of 10 years in federal prison and $250,000 in fines.
The players
Kenneth Currin Schuchman
The 21-year-old defendant, also known as Nexus and Nexus-Zeta, operated the Satori botnet.
Federal Bureau of Investigation
The federal agency that investigated the botnet conspiracy through its Alaska field office.
The details
Schuchman used his father's identity to evade detection while managing the botnet from Vancouver, Washington. The conspiracy scanned the internet to identify vulnerabilities, later flooding target networks with high volumes of junk traffic.
Timeline
July 2017 to October 2018: Schuchman conspired to develop and use the Satori botnet.
August 2018: Schuchman was indicted for his criminal activities.
October 2018: Schuchman orchestrated a swatting attack against a co-conspirator.
September 25, 2026: The guilty plea was reported in legal filings.
The Tech Race
This case follows the pattern set by the 2016 appearance of the Mirai botnet, which remains the primary historical benchmark for the weaponization of insecure IoT devices. The persistence of these variants demonstrates an ongoing arms race between cybersecurity defenders and attackers.
Users can reduce their risk by regularly updating firmware on routers and security cameras to patch known vulnerabilities. Neglecting these updates allows botnet operators to integrate personal home hardware into large-scale malicious traffic networks.
The takeaway
Securing home networks requires proactive management, as botnet operators constantly scan for outdated firmware in connected devices. Keeping all IoT hardware updated is the most effective defense against becoming an unwitting part of a global botnet.
Further reading
Learn more about the latest threats in Cybersecurity.
Source note: This article includes information reported by Briankrebs.
Live Poll
Do you trust the security of internet-connected devices in your home?










