Are all those infected machines, that create the DDoS attack, tracked and labeled? I.e. is their cover now blown? Or do they live on to attack another day?
For example somebody has a Memcached instance running on a public machine and does not realize they have UDP ports on 11211.
"Memcrashed - Major amplification attacks from UDP port 11211": https://blog.cloudflare.com/memcrashed-major-amplification-a...
Incompetent participants, but non notwithstanding still innocent.