The steganography takes advantage of x86 instructions where you can swap the source and destination by replacing an instruction like hex 31 c0 with 33 c0. The difference is bit 1, the direction bit, supported by many instructions.
Internally, the 8086 has 5-bit registers that specify the source and destination, typically a register. [1] The source and destination register get their value either from the register specification in the instruction (bits 5-3 or bits 0-2), or values in the microcode.
The clever part is the outputs of the source and destination registers go through multiplexers that can swap them. If the instruction has a direction bit, and the direction bit is set, then accesses to the source and destination registers are swapped.
The point of this is that the microcode doesn't know anything about direction swapping, so it is implemented "for free" as far as microcode size (but with the addition of the swapping circuit).
The 8086 has a "Group PLA" that categorizes instructions into groups; one of these groups is "instructions that have a direction bit". This prevents direction swapping from happening for instructions where it is not supported.
I hope this explanation makes sense; it should probably be a blog post :-)
[1] You might wonder why source and destination are specified with 5 bits when the instructions use 3 bits to specify the register. The first reason is that many registers can be accessed as half-registers, so you need another bit. (This bit comes from the byte/word specification bit in instructions.) Second, this mechanism is used to access the other 8086 registers, not just the general-purpose registers. Third, there are also invisible temporary registers that also need accessing. Thus, the internal register specifications are 5 bits.