Arrests can weaken coordination, slow recovery, and disrupt monetisation, but intact infrastructure can keep the threat alive. Remaining servers, domains, and infected endpoints may still support criminal clients, including ransomware operators and DDoS renters. The result is often a partial degradation of capability rather than a permanent collapse, especially if enforcement action is not sustained.
Why a Botnet Can Survive the Arrest of Its Operators
A botnet is not just the people running it. It is also the domains, servers, redirectors, bulletproof hosting, infected endpoints, and payment or tasking channels that keep it functional. If those components remain online, the arrests may disrupt command and monetisation, but they do not automatically remove the capability to issue tasks, recover access, or hand the infrastructure to another operator.
The practical question is whether the arrest removed the operational command structure or only the current managers. In many cases the latter is true, which means the threat becomes degraded rather than eliminated. That is why takedowns often need follow-on work against hosting, domain control, and downstream criminal customers.
What Usually Keeps the Threat Alive
When the infrastructure is intact, the most durable assets are the ones that outlive individual arrests. Infected devices can remain enlisted, dormant servers can be reactivated, and domains can be repointed or migrated. If the botnet served multiple criminal clients, one service line may pause while others continue, especially when the operators used modular infrastructure or subcontracted parts of the stack.
This is why the difference between an operator arrest and a full disruption is often one of remaining control over the underlying access paths. Criminal infrastructure behaves like an abused platform: if the endpoints, credentials, and hosting relationships remain available, the network can be revived, sold, or re-tasked faster than defenders expect.
- Surviving domains or DNS control can preserve reachability.
- Compromised endpoints can continue generating traffic or relays.
- Shared infrastructure can be rented to other actors.
- Stored logs, panels, and credentials can help a replacement operator resume operations.
Risk and Threat Considerations
The main risk is assuming that an arrest equals a collapse. If the supporting environment remains intact, the botnet can keep creating harm through spam, credential theft, DDoS, or ransomware enablement. The infrastructure itself can also reveal adjacent criminal relationships, so one seizure often exposes a broader ecosystem rather than ending it.
Failure mechanism: Enforcement removes a person or small group, but not the domains, servers, infected endpoints, or business relationships that make the botnet operational. Another actor can inherit, rent, or rebuild the remaining components.
Impact: The threat persists in a reduced but still meaningful form, allowing continued abuse, faster reconstitution, and ongoing risk to victims until infrastructure, monetisation channels, and access paths are all disrupted.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
MITRE ATT&CK address the attack and risk surface, while NIST CSF 2.0 and CIS Controls v8 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| MITRE ATT&CK | T1583 — Acquire Infrastructure | Botnet persistence depends on acquiring and retaining infrastructure. |
| T1071 — Application Layer Protocol | Botnets often retain command channels through common application protocols. | |
| T1489 — Service Stop | Arrests may stop operators without stopping the infrastructure itself. | |
| Recommendation — Track and disrupt infrastructure acquisition, hosting, and repurposing activity. Hunt for command-and-control traffic hidden in normal protocol use. Verify whether the adversary's operational services were actually disabled. | ||
| NIST CSF 2.0 | RS.MI — Mitigation | The situation requires coordinated containment and disruption beyond a single enforcement action. |
| RC.RP — Recovery Planning | Residual infrastructure means recovery must include sustained follow-through and revalidation. | |
| Recommendation — Coordinate mitigation actions that reduce residual attacker capability. Plan recovery steps that confirm the threat has not simply reconstituted. | ||
| CIS Controls v8 | CIS Control 17 — Incident Response Management | Botnet arrests need incident response follow-through against remaining infrastructure. |
| CIS Control 6 — Access Control Management | Residual botnet capability depends on surviving access paths and credentials. | |
| Recommendation — Use incident response processes to sustain containment after arrests. Revoke or rotate access paths that could restore botnet control. | ||
Practitioner Guidance
What to prioritise: Treat arrests as an interruption event, not a closure event. The first follow-up question should be which parts of the infrastructure remain online, who still controls them, and whether any infected population is still reporting back.
What to verify: Confirm whether the botnet’s domains, hosting, certificates, redirectors, and tasking endpoints were actually seized or sinkholed. If only the people were removed, assume residual capability remains until telemetry shows otherwise.
Practitioner takeaway: Effective disruption targets the operator, the control plane, and the money path together; removing only the person usually buys time, not safety.
Related resources from NHI Mgmt Group
- What happens when a cybercrime service is disrupted but its operators rebuild under new infrastructure?
- What happens when law enforcement disrupts malware infrastructure but the criminal ecosystem keeps the distribution channels intact?
- What happens when ransomware operators use centralized command-and-control infrastructure?
- What happens when a nation-state uses ORB infrastructure instead of a conventional botnet for espionage operations?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on September 20, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org