Well we would know who they are, they are already on this list
http://www.top500.org/ 
Sorry to sound sarcastic but even if they knock down the 2 biggest groups they would not practically be able to overcome the remainder of the network.
If any significant botnet owner decided to they could DDOS pretty much all the major pools. Most (all?) of the pool servers are run by small time operators who don't have the infrastructure needed to survive a big DDOS attack. Ditto hacking wise - one guy setting up a server and typing yum update now and then does not make a robust system. Once all the mining pools are offline the size of the problem is a lot smaller.