Of 18,000 backdoored servers, hackers followed up on only a few dozen
arstechnica.com
arstechnica.com
It seems like the operation was run on the cheap.
If hacking an antivirus will gain the attacker complete control over millions of potential targets, than the weakest link in millions of machines is also a bug in that antivirus software. There is a reason many experts recommending against installing anything besides Defender.
In retrospect, Solarwinds seems to have been a relatively weak link, but perhaps no less than Microsoft teams or other common enterprise software that are known to take security lightly.
And of course, less than any IoT device that might be practical to attack en masse.
These will continue to be targeted, and it is silly to say that anyone is "breaking norms".
Thinking about it, if you want secret information by definition only a tiny fraction of the networks out there are going to have it— anything most of them have wouldn’t be a secret anymore. So any attackers are going to focus the majority of their energy on exfiltrating data from the most likely/productive extreme minority of their infiltrated networks.