I'm just speaking from experience from a few of the older IRC botnets I analyzed for a few years. Nearly 200,000 of the 750,000 (+-150,000) bots were on dial-up connections in developing countries.
Now, 200,000 packets coming in at 2.8KB/s is nothing to joke about(500MB/s). Yet, 500 packets coming in at 8MB/s, well, on top of the arsenal of random connections.
I sometimes forget I'm a dinosaur now when it comes to this sphere of knowledge! I'm sure these days its less one sided. It used to be dialup and windows 95/98 RPC vulnerabilities spreading in the wild using IRC as a middleman.
With tor, torrents, etc, I imagine the game has drastically changed in the past 6 years. It is too bad there are not many jobs in this field, I would gladly make a lifetime out of it.
I was on a team that created an anti-bot-net which would reinfect, secure, and alert of the already infected machine. We determined that it could prove to be more destructive than the original botnet, because it wastes resources, while we could actually impact the way a machine behaved for the owner. This could also lead to legacy machines failing due to windows updates or firewall rules.