Botnet Takedowns Show Temporary Success as Operators Adapt to AI and Blockchain
A significant drop in botnet size in Q2 2026, following international law enforcement actions, may be short-lived as attackers leverage AI and decentralized technologies to rebuild infrastructure.

International law enforcement operations in March 2026 successfully disrupted major botnets like Aisiru and Kimwolf, leading to a dramatic decrease in the observed size of the largest botnets from 13.5 million devices in Q1 2026 to just 2.09 million in Q2. This marks the first time in over two years that the trend of ever-increasing botnet sizes has reversed, offering a moment of celebration for the cybersecurity community.
While the takedowns were a significant achievement, the decline in botnet size is likely attributable to a combination of factors. Beyond the direct disruption of command-and-control (C2) infrastructure, the heightened attention surrounding such operations often prompts increased efforts from ISPs, security vendors, and researchers to identify and remove malware from compromised systems. Routine network modernization and hardware replacements may also contribute to a gradual reduction in vulnerable devices.
However, the underlying economic incentives that fuel botnet creation remain largely unchanged. The persistent demand for Distributed Denial of Service (DDoS)-for-hire services ensures that botnet operators have a strong motivation to rebuild their infrastructure or establish new ones. Coupled with the continuous growth of internet-connected devices, many of which receive infrequent security updates, the supply of vulnerable systems remains abundant.
Adding to this challenge, advancements in Artificial Intelligence (AI) are making it faster and more efficient for attackers to discover, prioritize, and compromise vulnerable systems at scale. This technological edge, combined with the economic drivers, suggests that the observed decline in botnet size may be temporary, with operators adapting by abandoning disrupted infrastructure and creating new botnets to fill the void.
A significant adaptation observed is the shift towards decentralized, blockchain-based command-and-control infrastructure. Botnets such as Aeternum and Void are now utilizing smart contracts on networks like Polygon and Ethereum. This architecture makes traditional C2 takedowns far more challenging, as disrupting the command channel would require compromising the underlying blockchain itself—a technically and economically prohibitive task.
Furthermore, the geographic distribution of botnet activity is becoming more dispersed. In Q2 2026, the top three countries accounted for only 32% of DDoS attack sources, down from 47% a year prior. This makes country-based filtering a less effective defensive strategy, as operators can easily shift malicious traffic to compromised devices in other regions.
The evolving landscape of botnets, driven by economic factors, AI advancements, and decentralized infrastructure, necessitates a reassessment of defensive strategies. While takedowns are effective in the short term, long-term resilience requires addressing the root causes of botnet proliferation and developing more robust defenses against increasingly sophisticated and adaptable adversaries.