This is not bruteforce.
The flaw is the attackers used the same crypto algorithm but with smaller width variables. This rendered some of the crypto useless. Half of the total bytes in the keystream are always null and correspondingly half of total bytes in the ciphertext retain their original value. always
Even with 16-bit variables proper implementation would have made this a lot tougher.
As they say, Don't' roll your own crypto.