This was a sophisticated attack happening over 2 years, from knowing the current maintainer was emotionally vulnerable to the structure of using the build system to introduce the patched code to Linux distro repos.
I'm guessing Kaspersky will come to the same conclusions many others have; that this was a state actor or similiarly well heeled group.
Maybe Kaspersky is Russia backed and is filled with backdoors. Idk, and I don't care because I don't use their products. But I do know they have great security experts and when they publish analysis like thesez they are generally very complete and informative, like when they discovered the remote hack on iPhones thing: https://securelist.com/operation-triangulation-catching-wild-triangle/110916/