I don't get it. It is impossible to identify who receives the packets but TCP/IP requires an acknowledgement that the packets have been received before sending more packets. Surely the C&C could be tracked from this acknowledgement? Or were they using UDP?
Victim to decoy: syn
CNC to victim posing as decoy, after reading sequence number from message 1: syn ack
Victim to decoy: ack