After releasing the code overnight the report's writer found 420,000 suitable botnet endpoints ... The botnet was able to spread quickly and efficiently just using the four login combinations and was soon reporting back in healthy numbers.
That doesn't actually say he infected 420,000 machines, does it?