I hate to say this, but
It's time for Governments to get involved. There are too many networks claiming high standards of operation while taking in money to host craploads of illegal network abuse. It's at the regional networks, the hosting providers, and all the way up to the Tier 1 transit networks providing hostile networks with connectivity. Their attitude right now is that they absolutely don't care. No working abuse contact of any kind. Criminals pay money, victims don't.
I know the Internet is supposed to be self-healing but there's a practical limit to just how many firewall rules one can maintain. DDoS are difficult to block when there's a crime-friendly network one or two hops upstream. Companies pay CloudFlare or Akamai for protection while they serve the carders, phishers, and C&C systems helping to fund the attacks.
Yeah, the Internet is bad enough that I think Government intervention will make it better. Sad times.
https://www.abuseipdb.com/statistics
https://www.spamhaus.org/news/article/813/spamhaus-botnet-threat-update-q2-2021