Hajime vigilante is putting a huge amount of work into infecting IoT devices
arstechnica.com
arstechnica.com
Maybe it would be more believably whitehat if some fraction of infections just closed down vulnerable ports and disconnected from c&c or removed themselves.