From the linked paper, the 'trick' here is for the attacker to improperly respond to a tcp connection initiated from the target.
The standard handshake looks like:
Syn ->
<- Syn / Ack
Syn ->
The 'split handshake' looks like:
Syn ->
<- Syn
Syn / Ack ->
<- Ack
As a result, the hypothesis is that the intermediary router could incorrectly flip the roles of client and server, and incorrectly forward untrusted packets from the outside 'client'.