Right. They could possibly do this and have done it before. But they wouldn't need to request the source code from the author in order to do it - they could patch the binary. Also, it's a pretty involved thing to do and not that easy to pull off in a situation like this. For example, presumably all of the targets already have the software installed, and they may have no reason to visit the official site again; especially if updates are very infrequent.
Finally, it wouldn't do them any good for trying to crack things that are already encrypted with it, which from the conversation does seem like was at least one of their goals. (Could be deception, but that's the most likely reading, to me.)
I'm just saying that that doesn't seem to be a likely reason for requesting the source code.
The reason is likely what they said it was: they want to look at the source code to see if there's some way to crack the encryption faster than they otherwise could - for example, some bug causing key generation to be somewhat predictable.