To me, they do sound like the kind of things an attacker would want, if they found a reliable, reproducible, automatable path to them. If I was writing malware, ransomware, or just exfiltrating data, I'd be much happier to have root access to do it. Even simple botnets, I'd probably want to try to replace a regular service that most everybody runs (like cupsd) with one that functions exactly like the real one, but also does the malicious activity, and similarly try to patch the package manager to persist it on updates.