All corrections
1
Claim
It used to be that the worst thing these people could do was launch DDoS attacks against a particular target, or send spam email, or scrape for crypto and credit cards.
Correction

Historically, botnets have been used for much more than DDoS, spam, cryptomining, or credit-card scraping. Official DOJ records show botnets were already enabling ransomware, bank fraud, child exploitation, bomb threats, and other serious crimes years before this post.

Full reasoning

This sentence understates what botnet operators were already doing before the AI-driven future the post is discussing.

Official U.S. Department of Justice sources document that botnets have long been used for crimes far beyond DDoS, spam, cryptomining, or scraping payment data:

  • In June 2014, DOJ said the Gameover Zeus botnet was used to steal banking credentials and was a common distribution mechanism for CryptoLocker ransomware. DOJ said the FBI estimated more than $100 million in losses from Gameover Zeus, and described CryptoLocker as ransomware that encrypted victims' files and demanded payment.
  • In August 2023, DOJ said Qakbot was leveraged to commit ransomware, financial fraud, and other cyber-enabled criminal activity, and that it was used by major ransomware groups including Conti, REvil, and Black Basta.
  • In May 2024, DOJ said the 911 S5 botnet facilitated large-scale fraud, child exploitation, harassment, bomb threats, and export violations, including billions of dollars in fraud.

So the historical record does not support the idea that the worst botnet operators "used to" do was DDoS, spam, or scrape for crypto and credit cards. By at least the early 2010s, botnets were already being used for ransomware distribution, large-scale bank fraud, and other far more serious criminal activity.

3 sources
Model: OPENAI_GPT_5 Prompt: v1.16.0