Would have been cheaper to pay them off.

Give them the 10 BTC bounty so we can all go back to making money.

Are you really that ignorant to think that's how it works? They're spending money to ddos attack, if you start paying them why would they stop? Remind me to never hire you to be my hostage negotiator.
I am wandering what makes you think that they are spending money?
I do agree that paying ransom is not the solution but ....spending money....it sounds like you have internal info or what?
Having infected zombies participate in a DDoS is how they are most commonly detected and eventually fixed. Reporting huge amounts of IPs to ISPs, while most are ignored, will cause some infected users to get contacted regarding the fact that their computer is participating in illegal activities.
They're much more valuable when undetected and stealing user information (passwords, credit card numbers, etc.). So while executing a DDoS with your own swarm of infected machines might not actively cost money (though many DDoSes are actually somebody paying for another perosn's botnet to attack), it will lose them machines that could be generating money in ways which don't get detected as quickly.