What you're missing is that these attacks weren't targeted. They scanned internet and processed pretty much all accessible Exchange servers in the same manner. There were a few crews operating in parallel by the way which had access to same exploit chain but different exploits.
Some had certain variables hardcoded, e.g. Administrator user's name and their exploits worked with higher success rate in anglosphere, but failed in localized environments. Others had more advanced exploits which queried parameters instead of assuming them - those where more successful around the globe.
Another nuance missing from popular press is that most groups in China (and Russia) are operating independently, but share tradecraft among them and occasionally engage with politicized missions (either working on explicit orders from government handlers or simply defending their beliefs hacktivist-style). This is what FireEye means by "affiliation with Chinese government", NOT "operates strictly on government orders".