The botnet controller could be extorting websites directly... wire $5000 to my paypal account or your website will go down. Anyone from Posterous care to confirm/deny in this case?
It's not uncommon. There was an article a long time ago telling the story of a DDOS attack on a gambling website, and how a guy who was a philosophy major (iirc) figured out how to beat it, and then formed a company providing the same service. Forgot the url/title/etc, but it was good. Plenty more available with a search.