
This is no hoax, and people should be frightened. As a security consultant, one can never be paranoid enough. A cracker only has to be right once to find a chink in the armour.
Your computer and everything on it, business, personal, bank account details, private porn collection etc and your life is in someone else's hands. These persons could be very nasty indeed.
They could:
1. just delete everything while you're asleep and securely wipe the hard disk, but then there is no profit in it for them.
2. encrypt important files and ask for a ransom for the key. If they were nice, you might actually get the key. If not, then pray you had backups.
3. Use your machine to send spam messages.
4. Use your machine as a vehicle to distribute or child porn. If you get caught, it can ruin your life regardless of your innocence.
5. Listen to everything you do and grab your bank details and passwords.
6. Launch denial of service attacks from your machine to any number of targets.
7. Cause immense misery to millions of people, steal identities, use ebay in your name etc, take out mortgages in your name and disappear...
8. Do many other things too nasty to think about, such as blackmail or kidnapping if the victim is famous.
Users' ignorance and indifference to security is shocking, but why should they have to know so much? If Microsoft had done their job properly the criminals would never have got this much of a foothold and created such a huge criminal economy.
I suspect that the botnet is still inactive because it is too successful, and all the world is watching. The feds will be crawling over any ips found to be responsible for kicking it into action.