I saw that back in the 90's when I was a script kiddie myself. Programs that we use to hack others like back orifice or netbus were being distributed infected
Which meant all a potential victim had to do was accept the file, not run it (renaming the extension was a good first step), and note the IP address of the skiddy who sent it to them. Inspect the file to see the port and password configured therein, run the control program, connect back to the origin IP with the given port and password, et voila.
I wonder how many of them thought their tool was backdoored, not realizing it was they who had compromised themselves.