Real botnets at scale: vulnerable connected devices and command channels, not AI autonomy
Real botnets at scale: vulnerable connected devices and command channels, not AI autonomy
Primary comparison: US Justice Department, 19 March 2026, describes a multinational court-authorized disruption of command infrastructure for four already-operating Internet-of-Things botnets. Its court-document account says administrators had infected more than three million devices, mainly cameras, routers and recorders, some nominally behind firewalls; attackers sold device access and issued hundreds of thousands of DDoS attack commands. The takedown targeted domains, servers and administrators, aiming to prevent further infections and DDoS. The department does not report a measured fraction of cleaned hosts or prove the botnets cannot recover. Charges/allegations and the impact figures come from law-enforcement evidence; no claim of AI involvement is made.
Counterfactual relevance: this establishes that internet-scale, service-disrupting botnets already exist without autonomous frontier AI; a network firewall label alone does not block every downstream path. It does not establish that a particular AI agent can discover a comparable vulnerable-device population, obtain payload execution, install persistent agents and pay for/evade its controller’s inference. Conversely, law-enforcement domain seizures and administrator arrests can disrupt command channels but do not show that every infected endpoint is automatically cleaned or all future command networks prevented. Judge an AI-botnet forecast on incremental attacker labor, infection rate, durable control and defended services, rather than comparing one lab-funded intrusion to the existence of three million already-infected devices. Pathway synthesis.