It's true that they often use botnets, but amplification attacks are more and more common, and an important component here.
In these, the attacker sends crafted requests to an unwitting third party, and that third party then floods the victim with traffic. DNS amplification is probably the best known, here, since DNS is (usually) over UDP which has no persistent connection for replies:
- Send a DNS query to a DNS server, using your victim's IP address as the "source IP" for the query. Make the query something with a huge response, like using "ANY".
- DNS server responds to the victim's IP address, sending many big UDP packets with the response. After all, it can't know any better - it must* just trust the claimed source IP!
- Victim gets a huge flood of UDP traffic, overwhelming IP-level infrastructure like routers and switches.
This lets a relatively small attacker multiply ("amplify") their impact - and they do it while traversing a third party, making them more hidden.
---
* If course, there actually are mitigations for this; it's possible to detect this spoofing. But this is how DNS operators have worked in the past.