Anyone who's done anything related to security knows that it's impossible to discern much from any trace of an attack left behind - at best you might have IPs of proxy servers they used and you might be able to figure out the vulnerability exploited, but if the attackers were any good (and they're saying "evidence" suggests it's government agency level type stuff) - there is no chance they'd leave anything behind other than false traces to confuse the investigation.
Real evidence would be a corroborated confession, but even an excerpt of logs and/or a little description of what happened other than the "Cozy Bear" story would be great.
So basically someone hacks the DNC servers (and my guess would be that it should be trivial given that this is primarily a volunteer-operated organization), and NYT blames it on GRU. Because being hacked by Russia is cool, compared to being hacked by a nobody because your security is sloppy.
BTW - crowdstrike.com was registered in 2010 with GoDaddy, not exactly trust inspiring.