In the SANS report a research tries to discredit people who claim this is CIA or a US state sponsored operation, yet also claim there is clear evidence of a "signature" from "Cozy Bear" ... what is this signature? Shell code? A known compiler flag? FireEye and SANS have released zero information on this or anything that connects things to Cozy Bear.
Also from that report, there were excluded IP ranges that were all Microsoft IPs (not all of the Microsoft IPs, but all the ranges belonged to Microsoft).
Vault 7 shows the NSA and CIA are involved in domestic operations (and if you go back far enough Church Committee) and there is a chance this was a US based State Actor. Let's not forget about STUX.
The level of this attack was incredibly sophisticated. It had built-in delays for several days to avoid network sandboxing tests in the CI/CD pipeline. It was signed and released from Solarwinds CI/CD pipleine as well.
Let's not dismiss Snowden so easily and not realize this could have been an American state actor as well (or even the UK, the EU or any other "allay" or enemy).