Botnet busts more for stunts than security, expert says

Microsoft and Symantec made headlines in September and in the summer by taking down major botnets. Now, one expert calls their actions ineffective, and wonders if the only reason they happened was to garner good press.
Working backwards, Symantec announced in September that they used a vulnerability within the ZeroAccess botnet's code to take down a significant part of it. Their actions gained headlines, because ZeroAccess has existed since 2010, and had a foothold on millions of systems globally.
In a similar situation, Microsoft took out 88 percent of the Citadel botnet this summer, going to far as to send configuration files to the infected systems that forced them to connect to sinkholes, removing them from criminal control. At the time, Microsoft said that 40 percent of the computers that were part of the operation were cleaned of infection. However, there were those that said Microsoft's actions were nothing more than a clever PR stunt, and that they had no real impact on the threat landscape.