I don't think they were saying that this hack was created by NSO/anyone external, but that the expertise needed to find and exploit it in the wild, as has been happening, is likely that of NSO/someone external. I thought the exact same thing when I read that line, but the paragraph after that makes it look like the above suggestion. Given that this program is not open source and has an encryption layer on all its network traffic, I would say that it is at least somewhat hard to find and probably signifies some level of sophistication on the part of the attacker abusing it.

