I am always wondering how those backdoors are discovered without internal leaks, fuzzing or enumerating all instructions bytes seem like too random.
Google “sandsifter”
Google “sandsifter”