From what I have read so far: speculative, at best.
Itβs all based on the sophistication, the level of psychological manipulation, years of effort, multiple actors, and a working theory based on commit timings.
Generally speaking, with attacks of this sophistication, if it's not a state-backed APT, it's someone who operates with the unofficial backing of a government to give plausible deniability.
I suppose it could be a few amateurs who took on a passion project, but... it's unlikely.
Could be someone at a company that hacks into stuff and sells it to governments too. They're always looking for backdoors and I assume would do stuff like this.
Is that actually known?