That's not the relevant bit. This is the relevant bit (emphasis mine):
"As far as we can tell, before releasing their malicious codes to attack victims, the attackers tested them against all of the relevant antivirus products on the market to make sure that the malware wouldn’t be detected."
This means that they can be certain they've bypassed the signatures, and whatever imperfect heuristics are being used have been bypassed, with the attackers essentially having all the time in the world to play with and understand the heuristics, up to and including a complete disassembly of the heuristics if necessary. And you can't have perfect heuristics (hi, halting problem!).
Yes, when the enemy has full access to all these things and sufficient resources to use them, the antivirus loses. Other malicious hackers don't have this scale of resources, and that's the sole reason they can't do it.