ICMP ECHO has an additional payload field thay we often ignore.
Some malware is known to use the ICMP payload as a C&C channel, or to tunnel out stolen information:
https://en.wikipedia.org/wiki/ICMP_tunnel
It also often gets overlooked, so while "you can tunnel inside almost any protocol", it is very common for malware to use ICMP for C&C.
This isn't to say ICMP should be blocked completely. But limiting the size and the value of the payload in ICMP ECHO requests and replies can definitely help.
This is not true in the slightest.
And it'd only be realistic on windows as all other prevalent platforms require administrative privileges for such.
Lets be real here, ICMP is a particularly bad protocol for malware and that's why nobody uses it.