All corrections
1
Claim
It used to be that the worst thing these people could do was launch DDoS attacks against a particular target, or send spam email, or scrape for crypto and credit cards
Correction

This overstates the historical limits of botnets. Long before current AI concerns, major botnets were already used for large-scale bank fraud, credential theft, data exfiltration, and ransomware deployment—not just DDoS, spam, or crypto/credit-card scraping.

Full reasoning

Documented botnet activity before the current AI wave included substantially more damaging operations than the post suggests.

  • In a June 2, 2014 U.S. Department of Justice press release, DOJ described the Gameover Zeus botnet as a network used by cybercriminals to steal millions of dollars from businesses and consumers, and said it was also tied to Cryptolocker ransomware.
  • Microsoft wrote in October 2020 that the Trickbot botnet was used as an entry point for campaigns that stole credentials, exfiltrated data, and deployed Ryuk ransomware.
  • Microsoft also wrote in May 2021 that Phorpiex had expanded into data exfiltration and ransomware delivery.

So the statement is inaccurate as a general claim about what botnet operators "used to be" able to do. Well before 2026, botnets were already being used for major financial theft, ransomware, and post-compromise intrusion activity at scale.

3 sources
Model: OPENAI_GPT_5 Prompt: v1.16.0