I think you're too focused on the technical side of things. If your target can be breached with an intern's hobby projects, why not breach your target with an interns hobby project?
That means you have more money to spend on analyst, translators, future operations, etc. You only start developing more capabilities if your targets need more capabilities.
Many important targets today are still being breached by a bunch of office macro's that have been around for ages. Still works, still yields desired results, no need for a passive global adversary or a l33t 0day.
You're getting concepts mixed up. These aren't exploits. You can't breach a target with them. They're post-exploit persistence tools. A persistence tool has just three jobs:
1. Enable the mission.
2. Avoid discovery.
3. Frustrate attribution.
These tools are amateurish. By modern standards, all they accomplish is (1). But rootkit.tar.Z for SunOS 4.1.3 did that too.
Presumably, if the CIA is implanting backdoors, they're doing it in high-stakes situations: the kind where it's important they not be identified, and the kind where it's important that identification of a single compromised machine not instantaneously provide a signature that can be used to identify every other compromised host in their inventory. But, nope.
One obvious possible subtextual revelation from the CIA tool kit that we've seen is that they're not doing high-stakes implantation work at all, and this stuff is all aspirational.
What is the possibility that this was a deliberate leak meant to obfuscate the true state of the art of what the CIA uses? Would that be too much of the trap of "hyper-competence" or the kind of thing you'd hope-for/expect-from an intelligence service?
True, keeping your enemies in the dark about your true capabilities is a useful strategy (unless it is a doomsday device, then you should tell the world). Strategic leaks of misinformation is one way to go about it.
Also low-quality exploits could be made on purpose to be intentionally found. The victim finds it and then thinks they are in the clear, while the a more sophisticated real exploit is lurking undetected.
That means you have more money to spend on analyst, translators, future operations, etc. You only start developing more capabilities if your targets need more capabilities.
Many important targets today are still being breached by a bunch of office macro's that have been around for ages. Still works, still yields desired results, no need for a passive global adversary or a l33t 0day.