Botnet Takedowns Are Working — But DDoS Operators Are Already Adapting

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Spread the love

Every time a major botnet is dismantled, the cybersecurity community celebrates—and rightly so. These operations are technically complex, require international cooperation, and make life considerably harder for cybercriminals.

The problem is that their success is often measured by what disappears rather than by the threat that remains.

Recent observations from Q2 2026 illustrate why that distinction matters.

For more than two years, every new record seemed to eclipse the last. The largest botnets we observed grew from 136,000 devices in 2023 to 228,000 in 2024, then to 5.76 million in 2025, and finally to a record 13.5 million devices in Q1 2026. Then, for the first time, the trend reversed. In Q2, the largest botnet we observed consisted of just 2.09 million devices.

The timing strongly suggests that one of the factors behind this decline was the coordinated international operation carried out in March 2026 by law enforcement agencies in the United States, Canada, and Germany. The operation disrupted infrastructure used by several notorious botnets, including Aisiru and Kimwolf, demonstrating that coordinated international action can successfully disrupt even the largest cybercriminal ecosystems.

In that sense, the takedown appears to have worked. But the more important question for defenders is what happens next.

Beyond the C2 Takedown

Of course, disrupting a botnet’s command-and-control infrastructure was a major step. However, it is unlikely to fully explain the scale of the decline observed during Q2 2026. Other factors were likely at play as well.

Major law enforcement operations often attract significant public attention, prompting Internet service providers, security vendors, CERTs, and researchers to intensify efforts to identify infected devices, distribute security updates, and remove malware from compromised systems. Routine hardware replacement and network modernization may also gradually reduce the number of vulnerable devices connected to the Internet.

While it is impossible to determine the precise contribution of each factor, the combined effect provides the most plausible explanation for the decline observed during Q2 2026.

The harder question is how durable that change will be.

The Economics Still Favor Attackers

There are good reasons to believe this decline may prove temporary. The underlying conditions that enable large botnets to emerge remain largely unchanged, while new technologies are increasingly working in attackers’ favor.

The fundamental reason is that the demand for DDoS attacks has not disappeared. As long as there are individuals and organizations willing to pay for DDoS-for-hire services, botnet operators will have a strong incentive to rebuild lost infrastructure or create new botnets altogether.

On the supply side, the cost of building and operating botnets continues to decline. The number of Internet-connected devices continues to grow worldwide, and many still receive infrequent security updates or remain vulnerable long after known flaws have been disclosed. Meanwhile, AI-powered automation is making it faster and more efficient for attackers to discover vulnerable systems, prioritize targets, and compromise them at scale.

As a result, the question is no longer how quickly a particular botnet can recover after a takedown. In many cases, operators simply abandon disrupted infrastructure and build new botnets instead. Other operators may also step in, seeing an opportunity to fill the market gap. Ultimately, what matters is that the economics increasingly favor attackers. As long as these conditions remain unchanged, new large-scale botnets will continue to emerge.

How Blockchain Is Changing Botnets

Rebuilding is only one form of adaptation. More importantly, some operators are redesigning botnet infrastructure around the very weaknesses that takedowns exploit. 

One of the most significant developments we have observed this year is the shift from traditional command-and-control infrastructure hosted on the public Internet to decentralized, blockchain-based alternatives.

Botnets such as Aeternum and Void illustrate this trend. Instead of connecting to a dedicated C2 server, infected devices monitor smart contracts deployed on the Polygon and Ethereum blockchains, respectively. Those smart contracts contain encrypted instructions or pointers to additional infrastructure, allowing operators to distribute commands without relying on a single server that can be seized or taken offline.

The choice of blockchain is no coincidence. Polygon and Ethereum are among the world’s largest blockchain networks, supporting vast amounts of legitimate economic activity. Disrupting the command channel would ultimately require disrupting the underlying blockchain itself — something that is neither technically feasible nor economically acceptable.

This does not make blockchain-based botnets impossible to investigate or dismantle. It does, however, make one of the most effective elements of traditional takedowns — disrupting command-and-control infrastructure — significantly more challenging.

Geography Is Becoming a Weaker Signal

The architecture of botnets is not the only thing changing. Their geographic distribution is evolving as well. Just a year ago, in Q2 2025, the top three countries accounted for 47% of all application-layer DDoS attack sources, while the top 20 represented around 76%. Fast forward to Q2 2026, and those figures had fallen to 32% and 70%, respectively.

In practical terms, this makes country-based filtering a much weaker defensive tool. Blocking traffic from one region does not necessarily stop an attack when operators can shift activity to compromised devices elsewhere. As malicious traffic becomes more geographically dispersed, origin alone tells defenders increasingly little about whether a request is legitimate or malicious. 

Building More Resilient DDoS Defenses

The broader lesson is that defenders should be careful about treating the visible size of the botnet ecosystem as a proxy for DDoS risk. A smaller botnet does not necessarily mean a less capable attacker, just as a successful takedown does not necessarily translate into a lasting reduction in attack capacity. 

As botnets become more geographically diverse and more resilient to disruption, organizations should assume that large-scale DDoS attacks will remain a persistent risk rather than an occasional event.

That means preparing for attacks across multiple layers simultaneously. Modern DDoS campaigns increasingly combine high-volume network-layer attacks with sophisticated application-layer techniques designed to exhaust server resources while bypassing traditional filtering. Effective protection therefore requires coordinated defenses across both the network and application layers.

Organizations should also avoid relying too heavily on country-based traffic filtering. As attack sources become more geographically diverse, geographic origin alone provides increasingly little information about whether traffic is legitimate or malicious. Behavioral analysis, adaptive filtering, and continuous traffic inspection offer a much more effective foundation for modern DDoS protection.

Botnet takedowns remain important, and the sharp decline observed in Q2 shows that coordinated international action can have a real impact. But takedowns should be viewed as disruption, not eradication. The challenge for defenders is not to wait for botnets to disappear, but to build infrastructure that remains resilient as attackers rebuild, decentralize their operations, and diversify the sources of malicious traffic.

Author: Andrey Leskin, CTO at Qrator Labs

Andrey Leskin is the CTO at Qrator Labs. With over a decade of experience in commercial development and high-performance hardware and software solutions, he has been with Qrator Labs since 2013, advancing from developer to CTO. Andrey oversees product management and technological strategy, playing a pivotal role in shaping the company’s innovative approaches.

The post Botnet Takedowns Are Working — But DDoS Operators Are Already Adapting appeared first on Cyber Security News.