Because DDoS attacks are not easy to police. Technically the users infected with the trojan are just as much to blame, as they are responsible for how their connection is used. At the end of the day though, I doubt that someone will be sent to prison because they got owned.