I'm guessing of course, there's not much real details to go on, and that would mean this infection is more then just a malicious BIOS.
EDIT: Or he's full of shit. Honestly I said that several times reading it, the story was clearly written for sensationalism and made many seemingly impossible claims. I'm no where near an expert but it still set off the bullshit meter too many times.
Hm. I suppose this is theoretically possible, but I don't see why it would be done in a practical sense. If the malware needs to "phone home", it doesn't need to send packets via localhost; it just sends them out on whatever interface is connected to the Internet. (But how would you distinguish those packets from any others being sent out to the Internet?) If the malware is divided up into multiple processes that need to communicate with each other, why would they betray themselves by connecting via localhost? If they are on OS X or Linux, they can use Unix sockets, which don't need to go through any network interface. If they are on Windows, they can use any of several Windows IPC mechanisms that don't require a network interface.