Most of these are *not* retail operations, no. But even the retail ops aren’t using domains and domain controllers when they’re small to medium sized.
(Which can explain where all of these exploited card numbers are coming from.)
And how the botnets that are launching the spam and phishing attacks can grow to a million+ machines.