All corrections
1
Claim
It used to be that the worst thing these people could do was launch DDoS attacks against a particular target, or send spam email, or scrape for crypto and credit cards
Correction

Historical botnets were not limited to DDoS, spam, and crypto/card scraping. Long before current AI concerns, major botnets were used for banking theft, credential harvesting, ransomware delivery, and other automated fraud.

Full reasoning

This sentence overstates how limited pre-AI botnets were.

Multiple official sources show that botnets have long been used for more than DDoS, spam, and scraping cryptocurrency or credit-card data:

  • In 2014, the U.S. Department of Justice said the Gameover Zeus botnet was used to steal millions of dollars and to funnel stolen banking credentials back to its operators.
  • In 2017 and 2018, the DOJ said the Kelihos botnet was used not just for spam, but also for harvesting login credentials and installing ransomware and other malware.
  • In 2023, CISA and the FBI said QakBot began as a banking trojan stealing banking credentials and later evolved into a multi-purpose botnet capable of reconnaissance, lateral movement, data gathering/exfiltration, and ransomware delivery.

Those are all examples of botnet operators doing substantially more than the narrow list in the post. Because the claim says the worst thing botnet operators "used to" be able to do was DDoS, spam, or scrape crypto/credit cards, it is contradicted by well-documented historical cases of botnets being used for large-scale banking fraud, credential theft, ransomware deployment, and broader intrusions.

3 sources
Model: OPENAI_GPT_5 Prompt: v1.16.0