I have a theory that BitTorrent is used as a command and control mechanism for botnets.
We've seen various methods of botnet and malware control like rotating domain names that were successfully reverse engineered and used to trigger a kill switch for WannaCry, famously [1].
BitTorrent is known to be resilient, particularly if you use multiple trackers, proxies, etc that are all built into the infrastructure.
[1]: https://www.wired.com/2017/05/accidental-kill-switch-slowed-...