Rather self inflicted
If you operate world's most unsafe OS for decades without doing anything serious about it because it keep customers subscribed to please, please, please get the next patch (which breaks new things) then I'd say you have literally enabled these criminals yourself.
A DDoS botnet is comprised of compromised systems, and which OS needs more online bandwidth just to keep up with the patches? Yes, that one.
So, from an enterprise risk perspective you don't just run the risk of a breach and accompanying costs in recovery and possible fines under DORA and GDPR, you also may find your bandwidth being used when you're colluding with criminal exercises - or being attacked by other victims who are in a similar position.
Wonderful. Remember, you were warned. It was your choice anyway.
Meanwhile, the company partly responsible (don't forget IoT) keeps raking it in because they can dodge any responsibility..
Dammit, I blew my rant quote for the week. Worth it, though.