I'm reminded of a story about the tunnels of Viet Nam...
The VC and NVA were prodigious tunnelers. IIRC in 2 regions the US formed "Tunnel rat" units to chase them down the (small) holes and help destroy them.
They never eradicated the threat.
In the 3rd area they used all the troops to form a perimeter then set up a skirmish line doing a fingertip search of the ground not only for trap doors but also breathing hole. The marked every point.
Then they blew the whole lot up in one go.
AFAIK they did not have any further problems.
IOW you have to be very coordinated to eliminate a bot net completely.
But the infosec people can work together as a team in ways the (illegal) malware writers cannot.