They describe a microcontroller the size of a decoupling capacitor that is installed between the main CPU and main memory (as far as I can tell from the vague description).
I assume this would have to be done without layout changes. On a part of the board that is quite sensitive to layout changes. It just doesn’t seem likely that you’d do a hack like this. You’d need a micro controller or ASIC that was running as fast as main memory. You’d need to make it cope with different kernels... and edit memory such that remote servers could reliablely be contacted.
Why not just swap out some other part? Like the IPMI controller? Or the Ethernet controller? Something that has access to main memory, that would hide the functionality even better, and that would give the attacker more space to work with?
I don’t get it.