Persistent (and silent) hacks are kept out of the public’s eye because they get sold for six figures and higher. As soon as one of those becomes public, they are essentially worthless.
Once you own the T2 you can just disable secure boot and modify macOS anyway (like injecting EFI apps/drivers into the EFI System Partition).
A backdoor in there can wait for the user to type in their full disk encryption password, mount the disk, replace the kernel binary with a malicious version and then boot the system.
For good measure, repeat the above steps upon each system boot in case a system update or something overwrote the backdoored kernel.
---
This is actually similar to how Computrace/LoJack worked, except that one didn't defeat full disk encryption and would only place its payload onto unencrypted disks.
It is impossible to untethered persist a modified version of MacEFI without another exploit on the T2 since it has to be signed by Apple and the signature is properly checked.
I mean, you can just ad-hoc sign?
That's assuming they haven't just attached it to the port from the inside. Or, for that matter, replaced the entire logic board with their own, having used some less subtle attack against the original to extract and copy its secrets/data.
You can't really trust anything an attacker has had unsupervised physical access to.