However, some of these attack groups follow specific patterns, use specific IP addresses, domains, emails, etc. because there is no real consequence to them doing so. Kaspersky, Mandiant et al [1] often have great writeups on these types of things that are often posted to their own blogs and to netsec-related mailing lists that show some of these common attack patterns.
On top of this, Twitter could have been tipped off by law enforcement or intelligence.