It is much more likely that this backdoor would have gone unnoticed for months or years. The access this backdoor provides would be used only once per system, to install other APT (advanced persistent threats), probably layers of them. Use a typical software RAT or rootkit as the first layer. If that is discovered, fallback to the private keys you stole, or the social engineer the company directory you copied. If that fails, rely on the firmware rootkit that only runs if it's timer hasn't been reset in 6 months. Failing that, re-use this backdoor if it's still available.
My bet would be that they were after a crypto exchange(s) where they've already compromised some level of access and want to get deeper into the backend.
>Even if the backdoor had gone into production servers it would have been found fairly quickly if used at some scale.
I agree. Yes it's possible the backdoor could've gone unnoticed for months/years but I think the perp would've had to assume not.