Doesn’t even need to be at Amazon’s factory in China of where ever. But that is largely feasible too.
The difficulty is more about data exfiltration. Has to be appended to some real ‘normal’ request the next time a legitimate use of the mic is made, then piggybacks uploads on that connection.
Recording all times when a voice is heard would also massively increase the payload sent to the server. If you were just passively network monitoring it could stick out. Which is not something nation states want.
Forget these smart home mics, if I was a nation state I’d just stick with the mobile phones and laptops every person uses.
People are already paranoid about their Alexas inherently (and far more likely to potentially care to look) making them a poor target for hacking. It’s far more useful to turn the thing they carry around with them 24/7 into an active microphone with GPS, and plenty of more exfiltration possibilities with any mobile and desktop OS network traffic.
First, this generally means that when depowered, the output signal line is connected to ground by the ESD protection path.
Second, the actual mechanism which picks up the audio is generally variably capacitive-- a few picofarads-- in MEMS mics, and requires a pretty high bias (~15-200V) voltage to induce a usable signal for the in-package amplifier to be able to pick up the audio.
To not only have the in-package amplifier turned off, but also no significant bias voltage across the microphone electrodes, and somehow pick this up on the other side of the trace would be somewhat miraculous.