Anyone with a botnet this large effectively has a kill switch on Tor.
If this botnet actually relies upon Tor for its primary means of C&C, and the botherders are in fact motivated by ordinary financial crime, then it would seem to be the largest botnet that would be least likely to try to shut down Tor.
The most dangerous scenario for Tor is if this botnet continues to grow exponentially, its operators command it to go into an uncontrolled DDoS mode, or some other glitch in its software causes Tor to fall over. The C&C hidden service would become unreachable, the operators could lose control of their botnet, and it could end up essentially stuck in a perma-DoS mode upon itself and Tor.