Tools to fake such attribution and evidence were literally part of the leaked NSA/Equation Group toolkit.
I had only previously heard [0] that similarities in the tools were discovered by Kaspersky, not that there were any leaked docs that pointed the finger back at NSA themselves. Are you maybe thinking of PRISM/Wikileaks?
[0] - https://arstechnica.com/information-technology/2015/02/how-o...
And there are most likely a lot of cases where:
1) "...we got more than that," and...
2) ...data from "IPs and tools that are easily faked" is the only information that could be released publicly without compromising sources and methods.
It's a hopeless wish to want to be able to independently assess (as an amateur!) intelligence findings in all cases. If trusting the official assessments isn't acceptable (cross-checked with general knowledge of the situation), about the only reasonable alternative position is to remain agnostic.