www.lesswrong.com/posts/gutiw8MBrYDiD2u5z/models-finding-software-vulnerabilitie...
1 correction found
It used to be that the worst thing these people could do was launch DDoS attacks against a particular target, or send spam email, or scrape for crypto and credit cards
This overstates the historical limits of botnets. Long before current AI concerns, major botnets were already used for large-scale bank fraud, credential theft, data exfiltration, and ransomware deployment—not just DDoS, spam, or crypto/credit-card scraping.
Full reasoning
Documented botnet activity before the current AI wave included substantially more damaging operations than the post suggests.
- In a June 2, 2014 U.S. Department of Justice press release, DOJ described the Gameover Zeus botnet as a network used by cybercriminals to steal millions of dollars from businesses and consumers, and said it was also tied to Cryptolocker ransomware.
- Microsoft wrote in October 2020 that the Trickbot botnet was used as an entry point for campaigns that stole credentials, exfiltrated data, and deployed Ryuk ransomware.
- Microsoft also wrote in May 2021 that Phorpiex had expanded into data exfiltration and ransomware delivery.
So the statement is inaccurate as a general claim about what botnet operators "used to be" able to do. Well before 2026, botnets were already being used for major financial theft, ransomware, and post-compromise intrusion activity at scale.
3 sources
- U.S. Leads Multi-National Action Against “Gameover Zeus” Botnet and “Cryptolocker” Ransomware, Charges Botnet Administrator
The Justice Department today announced a multi-national effort to disrupt the Gameover Zeus Botnet – a global network of infected victim computers used by cyber criminals to steal millions of dollars from businesses and consumers... In a separate action... officials worked together to seize computer servers central to... “Cryptolocker,” a form of “ransomware.”
- Trickbot disrupted | Microsoft Security Blog
The Trickbot infrastructure was made available to cybercriminals who used the botnet as an entry point for human-operated campaigns, including attacks that steal credentials, exfiltrate data, and deploy additional payloads, most notably Ryuk ransomware, in target networks.
- Phorpiex morphs: How a longstanding botnet persists and thrives in the current threat environment | Microsoft Security Blog
From 2018, we also observed an increase in data exfiltration activities and ransomware delivery, with the bot installer observed to be distributing Avaddon, Knot, BitRansomware (DSoftCrypt/ReadMe), Nemty, GandCrab, and Pony ransomware, among other malware.