It is worthwhile to apply the same scepticism for placement of attribution as was applied with the Sony hack. In the latter many security analysts question NK attribution based on the similarity of code argument given by the US -- pointing out that the code base was in the wild for a long time, could be purchased on black market or reverse/reengineered after picking up the malware from a vulnerable machine. Shouldn't…
Just playing devils advocate here.
The alternative is to do as the USG did and immediately jump to conclusions based on not that great evidence. If they don't give others the benefit of the doubt why should we give it to them?