It’s because they made a rather cheap Linux VPS that is extremely easy to get up. It’s 4 clicks on DO (login with GitHub, click new droplet, click $5, click create), vs 15 clicks on Azure or AWS (where you have to create a bespoke account, go through the silly billing configuration, etc) where they expect you're running all of this past your procurement people and that they’ll want to configure stuff too.
Malicious bots would be 2nd.
I've never learned why DO is a malicious traffic leader. Maybe they're competing with OVH to be the next MCColo.