This has nothing to do with ‘average groups’. Regardless of who was behind it, it would have been 1 or a few people involved on a ‘need to know’ basis. And it is far from the only attack on Linux/Open Source. This one was underestimated: https://forums.theregister.com/forum/all/2011/08/31/linux_kernel_security_breach/