Also, let's just assume that a bad actor would have access to reasonably sized and geographically distributed botnet... they could easily run their own global connectivity tests to get a good picture of what the actual impact of their actions were.
We all have access to such a botnet. (And we should probably all participate in it, too.)
https://atlas.ripe.net/
We all have access to such a botnet. (And we should probably all participate in it, too.)
https://atlas.ripe.net/