Earlier quoted context omitted.
The sophistication cited by CrowdStrike was the actions taken on the DNC servers, not the initial penetration.
Exactly, why burn zero-days when you're targeting a technologically unsophisticated adversary with a huge organizational attack surface? Sure, HDD firmware hacks are cool, but in terms of R&D time far less efficient if you're willing to spam attempts to get in the front door. And I'd say they chose the appropriate level of sophistication given the success of the penetration. The DNC isn't exactly an air-gapped Irania…
Then how is this evidence of a 'state-sponsored actor'?
And how did the narrative of this story ever get derailed from what it should have been, which was, "The DNC, and John Podesta in particular who had both his gmail and his Twitter accounts hacked, are incompetent", to "this is Russian interference in a US election"?