Take it for what you will.
Take it for what you will.
There's very little indicating the author is Russian, but considering that's legitimately how most eastern European and Russian hackers type it wouldn't be much of a stretch.
However I can't see how that leads to the conclusion that the author is trying to pretend to be Russian, as opposed to just being from Ukraine, Romania or Russia.
And unless I'm missing something, there's even less information about his OPSEC practices.
1. Yandex is an email provider that is almost exclusively to the new Russian sphere of influence.
This is a the first thing that would jump out to an attribution analyst. Combined with the non-native language mistakes, a first pass analysis would indicate Russia.
But the name of the game is deception.
2. The "mistakes" in the text are not those which a Russian-speaker would make. The most obvious signal is leading space before the comma.