and for the existing IOT devices, are they the same thing, or were different exploits used for different devices?
Again, the speculation that it is IoT devices is unfortunately just that. However massive compromise of internet connected embedded device is not new: http://internetcensus2012.bitbucket.org/paper.html
I'm a bit concerned about the reliability of that report since there are no strong proofs for their claim.
http://blog.level3.com/security/attack-of-things/
Good luck updating those embedded linux devices, or even alerting the people who own them
and for the existing IOT devices, are they the same thing, or were different exploits used for different devices?