Read FireEye's reports about APT28 and APT29: http://www2.fireeye.com/rs/fireye/images/rpt-apt28.pdf https://www2.fireeye.com/rs/848-DID-242/images/rpt-apt29-hammertoss.pdf They are finding various correlations, such as Russian language settings, compile timestamps matching Russian work days, malware activity ceasing on Russian holidays... As a software developer, I can say that this "feels" par for the course for so…
You'd think that a state-sponsored attack would be a little less careless. This seems like a rookie give-away and makes me wonder if this is made to look like Russia instead of being Russia. When I think of a state-sponsored attack, I automatically envision something in the realm of Stuxnet in terms of quality and the level of sophistication.