"Site owners "would just see weird connections that don't seem to make sense," he said. "They look like they're trying to start an SSL handshake, but it comes in malformed and doesn't ever send anything after that first handshake attempt.""
Is it possible that they've found a flaw in a specific Systems handling of SSL and are trying to see if the flaw exists elsewhere in an attempt to produce an exploit? I'm not really a security guy, but it seems like they're up to something specific. Otherwise why use SSL exclusively? wouldn't they want to diversify their requests?