The bit you want to know:
> Their malware uses a little-known feature of RealTek audio codec chips to silently “retask” the computer’s output channel as an input channel
> Their malware uses a little-known feature of RealTek audio codec chips to silently “retask” the computer’s output channel as an input channel
Its a "feature" that they have sold to a lot of manufacturers as an ease of use thing for people who are frustrated because they plugged in their headphones but get no sound.
How does the computer know whether you've plugged a speaker or a mic into the port?
Even if the jacks are color coded or annotated, these day they are actually universal.
So it's more of an accidental backdoor.
The more convenient something is, and the more features it has, the easier it is to hijack it.
HDAJackRetask from alsa-tools is the tool for this on Linux.