What has empowered hacking of Kaspersky's network?

The recent case of hacking of Kaspersky's network involved, according to
media reports  
(http://www.theregister.co.uk/2015/06/15/duqu2_stolen_foxconn_cert /),
stealth of VeriSign certified private keys from FoxConn.

This is evidently only one possiblity. Wouldn't it also be possible, that
the criminal act was done already at VeriSign? Further, wouldn't it also be
conceivable that the bad guys empolyed much more sophisticated tecniques
than stealing in the common sense, in particular via exploiting backdoors
implanted by them in the RSA software being used (which is programming
technically not difficult to realize)?

M. K. Shen

