You might be surprised about how even the world's top intelligence agencies sometimes do make simple mistakes with domain and network registration which really are just genuine fuckups rather than false flag subterfuge. This is very rarely a matter of something silly like "Russian IP = Russian intelligence" and more like sloppily re-using an ostensibly non-attributable network or nameserver they didn't realize was already burned.
We're still kind of in the infancy of cyberwarfare. Attribution will probably be harder in a few decades.
But, yes, it's generally a matter of TTPs, target selection, goal analysis, and style.
For anyone curious, they have two excellent articles on this from a few days ago:
https://www.bellingcat.com/resources/2020/12/14/navalny-fsb-...
https://www.bellingcat.com/news/uk-and-europe/2020/12/14/fsb...
There was also an amazing investigation into this published yesterday by a Russian outlet, interviewing some of the black market data brokers and law enforcement officers (both of whom claim some of the brokers will be hunted and killed by the state, now):
https://translate.google.com/translate?sl=auto&tl=en&u=https...
To protect the source(s)?