> The IP address was linked to the GRU HQ itself. https://www.techradar.com/news/defending-against-nation-stat...
> one website that helped to coordinate them, StopGeorgia.ru, was hosted at an IP address that belonged to a company headquartered next to a GRU-connected military research institute https://www.wired.com/story/us-blames-russia-gru-sweeping-cy...
> Dragos researcher Joe Slowik noticed that one IP address identifying a server in Hungary used in that APT28 campaign matched an IP address listed in the CISA advisory https://www.wired.com/story/russias-fancy-bear-hack-us-feder...
> They used an Ip address that has been previously seen in other russian attributed attacks https://abcnews.go.com/WNT/video/ip-address-linked-russia-dn...
List would go on and on, and this is only for Russia. And yes I'm aware those sources are easily discarded as "non serious enough", as expected from the top results of a search engine I guess. Do your part and provide us with better sources.
Unfortunately, evidence is never provided beyond hearsay.