https://software.intel.com/en-us/blogs/2011/12/14/intelr-amt...
AMT is run in the management engine. "The Intel AMT functionality is contained in the ME firmware (Manageability Engine Firmware)."
So, yes, it's the ME that was exploited. AMT is just an app for the ME.