Once an attacker has gained root access to the device they can:
1. Access any data on the device regardless of application security (including applications that may request a separate password be entered as this password entry can be captured). This access includes logging into web services (e-mail included) pretending to be your phone and downloading or manipulating information stored or transmitted by the service.
2. Enable the microphone and cameras at any time.
3. Track location at any time via enabling GPS or monitoring for nearby WiFi, Bluetooth of cell tower device IDs.
4. Modify the user interface to report incorrect status, for example, incorrect battery level, GPS disabled when it's really enabled, incorrect data transfer amounts, etc.
5. Connect to other devices via WiFi or Bluetooth and interrogate them to find other devices or people nearby, and potentially attack those devices too.
An attacker can achieve similar outcomes with root access into other electronic devices--laptops, tablets, desktop computers, watches, TVs, WiFi-enabled LED light bulbs, home appliances, cars, etc. Obviously what can do with a device depends on the sensors contained within (must have a camera sensor to secretly take images or video).
Unless the attacker is reckless with turning on the video camera, microphone, GPS, WiFi, Bluetooth, etc all at once and draining battery much faster than expected, or transferring large amounts of data, you generally wouldn't notice anything different about your device. You would also probably have a hard time actively detecting the attack as the implant would be constantly watching for signs of debugging/investigation and disable/delete itself in such situations.
Generally the implant would be non-persistent only residing in volatile memory of the device that would be forgotten soon after the device is powered down. Regardless of persistence, capturing the implant from the device would be very difficult and expensive to perform for an individual, but within reach of a state actor or security researchers with a lot of time on their hands to accomplish should they have the patience.
It an implant were to be persistent and survive a device reboot, you could rapidly turn off the device (physically cut power from the battery), desolder the non-volatile memory chips and recover data similar to the process shown in [1]. There would be more steps involved if the device is encrypted (for example key is held in a TPM) but as you know the password to unlock the device, you could just ask the TPM nicely to give up the key. Failing that, there is FIB editing or other attacks against TPMs to recover keys. See [2] and [3] for some examples.
To detect a non-persistent implant, you'd follow a similar process but would have to quickly cool the volatile memory chip (see [3]) and then cut lines to the chip and insert new probes instead of desoldering it (the heat from desoldering would result in the volatile memory being cleared too quickly). Apple's Secure Enclave processor, as an example of a growing trend, encrypts and decrypts blocks of data stored in and retrieved from volatile memory so you'd additionally need to attack the Secure Enclave processor to retrieve the required keys to decrypt the volatile memory with.
The irony is that same security features which are designed to keep your device secure also inadvertently makes it prohibitively time consuming and expensive to inspect your device to detect a hidden implant in use. If you're concerned you could be a target (investigative journalists for example), the best approach is probably to assume the device is always compromised and use non-technological approaches to avoid or frustrate an attacker. Or perhaps you could find security researchers who'd love nothing more than finding and unraveling the secrets of a sophisticated implant (see [5]).
[1] https://www.youtube.com/watch?v=nXDUhhyY2rE&t=133s (recover data Samsung Galaxy directly from phone memory | HDD Recovery Services)
[2] https://www.youtube.com/watch?v=-vnik_iUuUs (Exposing The Deep-Secure Elements Of Smartcards | Christopher Tarnovsky | hardwear.io USA 2019)
[3] https://www.youtube.com/watch?v=M46Ol4gltbI (Focused Ion Beam TEM Lamella Prep Tutorial | Nicholas Rudawski)
[4] https://www.youtube.com/watch?v=Ej-Nr79bVjg (Cold Boot Attacks on Encryption Keys | J. Alex Halderman, Seth D. Schoen, Nadia Heninger, William Clarkson, William Paul, Joseph A. Calandrino, Ariel J. Feldman, Jacob Appelbaum, and Edward W. Felten | 17th USENIX Security Symposium 2008)
[5] https://citizenlab.ca/2020/12/the-great-ipwn-journalists-hac...