And it isn't too difficult for something to elevate itself to root anyways. It could just include a basic key-logger which would work on most systems and wait for your password. Unless you're on Wayland, you can see for yourself by typing `xinput list` and `xinput test <id>` using the id of your keyboard.
edit: and another comment linked to a blog post which also explains how this specific malware gains root https://www.intezer.com/blog/research/new-linux-threat-symbi...