Botnets definitely tend to patch or secure devices they've taken over. Plenty of them kill the ssh or telnet daemon after getting access, and some even patch known vulnerabilities in the web interface. It's a weird battle for control over someone else's hardware.
The Invisible Hand keeping your IoT devices chugging along... interesting thought!
It's not hard to imagine someone patching firmware out of sheer annoyance/efficiency. In fact, I bet someone can provide examples of product improvement along the journey of nefarious takeover.