Anyone having hard time swallowing this? They broke in and were totally undetected when they planted a... rootkit (unclear from article). While undetected they silently stole user credentials... Then to cover it all up, they ransomware'd the computer?
It's like breaking into a house and putting a bug in the wall, and then to cover the tracks you smash in the front door and leave the water running in the sink.
If the attacker was completely undetected, why intentionally jeopardize that?