That Guy wrote:
to remove this soap opera from a technical mailing list.
"Soap opera"? Apparently you are missing the point.
Obviously malware writers will use Tor for various purposes, but connecting to a C&C via Tor would not make sense since they have the largest anonymising botnet themselves. Hence, this could indicate a new piece of malware has been created that contacts its C&C via Tor to hide the IPs of the infected PCs. That would be beneficial to hamper gathering statistics and cleanup.
Sorry, if that hypothesis is not technical enough for your taste. Glad to hear that you have figured out what is causing the circuit creation storm. Care to tell the rest of us?
tor-node-moralfag-mailinglist
How nice...
// Yoriz