I have a hard time accepting that. Sure,if it was a financially motivated actor or common malware a few "high quality" indicators are all you need. But APT actors know they are being tracked by their adversary using these same indicators. It isn't difficult or costly for them to avoid reuse of infrastructure and tooling. The few attribtions I looked at in detail require a more speculative and somewhat imprecise correlation by humans as opposed to clear and static indicators.
Please correct my ignorance if I am wrong.
EDIT: Security companies do use "thousands" of signatures and indicators to find events that might possibly be associates with an APT group. Why is the NSA special? That's what I can't accept. As good as the NSA is,multi billion dollar security companies are not far behind (I would say some are even ahead when it comes to defensive security)