Furthermore, why brute-force crack crypto when you can inject code using the log4j exploit which transmits the private keys.
Sure log4j might have been recently patched, but it's not unrealistic to think that a nation-state has access to similar exploits.