> Read them again.
I just read them again. There is clearly a great effort being made to embellish the evidence so that it seems like state actor caliber work.
I think we can safely assume that the US and Russia conduct steady amounts of mischief toward each-other, and that it's largely out of the public view. Some of it likely includes hacking attempts, etc.
But the very documents you link say that while the groups in question were not previously linked to the Russian government, there is suddenly reason to believe they are (namely the release of the DNC emails).
So for some reason previous JARs had not felt it worthwhile to speculate about state actors being involved, suddenly this link to the Russian state became the most relevant aspect. Hmm.
I think it's quite plausible that Russia pays several groups of hackers a few million dollars a year to conduct mischief. For all we know the US pays similar (or even the same) groups to do mischief.
We're told that there is an arbitrary code execution vulnerability that was responsible for the DNC hack, but we're also told that a user fell victim to a phishing email. While both might be true, which of these pieces of evidence can we attribute to the DNC hack?
It was revealed previously that the server at the DNC was not patched and was likely vulnerable for many months. Any number of actors could have gained access to it, installed rootkits, etc.
With all the leaks and embarrassing revelations coming out about US intelligence agencies, I think it's best to remain highly skeptical of any information revealed that has a political impact.
A few months ago people were angry that James Comey handed the election to Donald Trump, now the same people are certain that the best explanation for the DNC email leaks is a Russian state-sponsored attack.
The truth is likely somewhere in the middle. Sure, Russia probably has a constant mischief campaign (as does, quite likely, the US), but within 24 hours of the DNC email leaks there were loud accusations of Russian involvement before Crowdstrike had done any analysis.
Reading the actual emails reveals an organizational culture that was extremely technically inept and that did not take it security seriously at all.
To put this in perspective, any serious state actor would have owned a vulnerable server being used by a major US political figure within hours after the server became vulnerable, and no trail would have been left. US intelligence warned the HRC about the vulnerable server multiple times because the US, a state actor, is on top of it.
How difficult is it to periodically scan the list of a few hundred IP addresses used by top officials for known vulnerabilities. This is by far the most plausible explanation for how a state actor would handle the situation.
If anything the FancyBear group and other similar groups are just hackers for hire who periodically sell some results to the Russian government.
I think it's important to consider that if you have the budget of a state actor you don't do many of the things that are used as evidence in this narrative.