My guess is this: two separate attacks occurred. The first attack involved compromising production, and installed a scheduled job that, at a certain time, would delete all database backups and code repositories, deschedule all workloads, delete all DNS records, etc. The next attack involves the fact that all source code is on managed workstations, so they compromised the IT management system to push malware to every machine globally at the exact same time that would destroy all git repositories (etc.) on the workstations. The result was that when the scheduled time occurred, production would crash and there would be no backups. (They must have wiped all the tapes at their offsite backup facility, too. I guess anything can be done for a price!)
To me, this sounds too complicated to even be feasible. I am still impressed when I edit some manifest with a new version number that 90% of the time that code eventually starts running. Being able to orchestrate a multiday outage just seems amazing to me, and that you'd make a lot more money being a cloud provider than a cybercriminal.
The other thought I had was that maybe they just kept thinking "we're so close to getting it back" for three days, rather than saying "everything is lost, revert to backups".