Research describes the botnet ecosystem fragmenting into more than twenty competing operations following disruption, with daily active DDoS endpoints climbing from roughly one million to eight or nine million over the past year.
That is the uncomfortable companion to the takedown files in this section, and it is the second time this desk has had to file it after the stealer resilience case in 26-0626.
Fragmentation Is A Worse Outcome Than It Sounds
A single large botnet is a big problem with a single point of failure. Twenty competing operations built from the same device pool are a similar aggregate problem with twenty points of failure, each individually smaller and therefore less likely to attract a coordinated international operation.
Competition between them also drives capability. Operators are selling to the same customers, so they compete on capacity, resilience and evasion — which is how features like the ledger-based coordination in 26-0707 propagate.
The Device Pool Is The Constant
None of the disruptions addressed the underlying condition. The compromised routers and cameras remained connected, vulnerable and unpatched, and were recruited by whichever operation reached them next.
The endpoint growth from one million to eight or nine million did not require new techniques. It required the same technique applied to a device population that keeps growing and never gets cleaned.
What Would Actually Change The Number
Enforcement against operators does not reduce the pool. Reducing it needs device-level intervention: mandatory security support periods, automatic updates that survive end-of-support, and provider-level detection of compromised customer equipment.
Each of those is a regulatory or commercial decision rather than a policing one, and none is currently being taken at the scale the numbers require.
This is an analysis file built on published research, listed below. Endpoint counts are vendor-derived measurements with stated methodology limits. Corrections: corrections@forensicpost.com.