www.lesswrong.com/posts/gutiw8MBrYDiD2u5z/models-finding-software-vulnerabilitie...
1 correction found
the worst thing these people could do was launch DDoS attacks against a particular target, or send spam email, or scrape for crypto and credit cards
This understates what botnets were already used for. Long before current AI, major botnets were used for banking fraud, credential theft, ransomware deployment, lateral movement, and data exfiltration—not just DDoS, spam, or simple theft.
Full reasoning
U.S. government sources directly contradict the idea that botnet operators were historically limited to DDoS, spam, or scraping crypto/credit cards.
- CISA's advisory on QakBot says it evolved into a "multi-purpose botnet" capable of reconnaissance, lateral movement, gathering and exfiltrating data, and delivering other malicious payloads, including ransomware.
- The DOJ's Qakbot victim-resources page says seized assets were tied to "payment of ransoms for ransomware attacks resulting from computer intrusions by members of the Qakbot conspiracy."
- CISA's alert on GameOver Zeus says the botnet was primarily used to harvest banking information, not merely for DDoS or spam.
So the historical ceiling for botnet abuse was already much higher than the post claims: botnets were used for serious intrusions, financial theft, and ransomware operations at scale.
3 sources
- Identification and Disruption of QakBot Infrastructure | CISA
Since its initial inception as a banking trojan, QakBot has evolved into a multi-purpose botnet and malware variant that provides threat actors with a wide range of capabilities, to include performing reconnaissance, engaging in lateral movement, gathering and exfiltrating data, and delivering other malicious payloads, including ransomware, on affected devices.
- Central District of California | RESOURCES FOR VICTIMS OF THE QAKBOT MALWARE
According to the allegations in the Complaint, the defendant assets are traceable proceeds of and were involved in money laundering offenses pertaining to the payment of ransoms for ransomware attacks resulting from computer intrusions by members of the Qakbot conspiracy.
- GameOver Zeus P2P Malware | CISA
GOZ, which is often propagated through spam and phishing messages, is primarily used by cybercriminals to harvest banking information, such as login credentials, from a victim's computer. Infected systems can also be used to engage in other malicious activities, such as sending spam or participating in distributed denial-of-service (DDoS) attacks.