The difference is that the ratio of abusive to legitimate traffic tends to be much lures with VPNs. Because a VPN isn’t 100% anonymous and just shifts the trust boundary to the VPN provider, most hard-core criminals won’t use them. So your traffic tends to be mixed in with folks who just want to pirate movies, watch Netflix shows that are only available in other countries, avoid geo-pricing surcharges, or who just care about privacy in the abstract. And then they use their VPN for all their web browsing, since they already paid for it. Tor is used by all sorts of folks who are trading kiddie porn, hacking into systems, scraping large quantities of data, buying & selling drugs, and doing other outright criminal things. Most abuse-detection systems care a lot about the legit:malicious ratio. An IP that is 95% legit but 5% malicious traffic will usually go through, as long as the malicious traffic doesn’t crash the system. An IP that is 80% malicious usually won’t.
When I browse through Tor, big websites like Reddit, Google, or anything protected by climate Cloudflare will 429 me, even if I’m just innocuously viewing a page or making a search in a regular browser. In a VPN, it almost always goes through, except for rare transient moments when somebody else is running a scraper through that endpoint.
Counterintuitively, it can often be better to use a system that is less secure, because lots of other people use the system with less security and so your actions get lost in theirs. Systems that are more secure are used by more hardcore criminals, and so they have more eyes on them. In these days of stochastic guilt, it’s often better to be doing naughty things in a law-abiding population than to be a legit user in a criminal population.
For this reason a large part of Mullvad's infrastructure is hosted by M247 Ltd. If you simply block that ASN you will block quite a large part of Mullvad. You can block the ASN by using one of the myriad services that allow you to query all the IP blocks assigned to an ASN.
It's also possible to simply enumerate all their servers. They have an API.
You might not get it all, but you can block a significant percent.
I've done it at work, this is on a blacklist of ASNs that require "extra" authentication