I find it interesting that this and a few other investigations have been released around times of great geopolitical tensions related to Russia. I think there are legitimate questions as to how/where this activity was observed and what led them to investigate it.
Personally, I don't know how closely they coordinate with Russian intelligence services, but some of the samples they get and the background/context they get can only be obtained if you are very close to the investigation. The way they phrase things like "we found this in a multi-engine scanner" raise the hair on the back of my neck, since I work in malware analysis and you don't just run across these types of samples by chance. They are either doing IR for organizations that were targeted (which you would just mention), or they are getting tipped off on where to look.
Whether or not this is intentional, or just happens to be a coincidence, it is something to be aware of.
Examples of suspicious timing: Flame paper released while there were massive protests in Russia around 2012, Regin/Equation Group/Duqu 2.0 paper released during Ukranian invasion circa 2014/15, and now this paper also released while tensions in Ukraine are ramping up and after the fallout from the SolarWinds stuff.
I think it would be less suspicious if places like Sputnik (a known propaganda arm of Russia) didn't immediately start pushing a specific narrative when Kaspersky has these malware releases.