Their answer is "probably the USSR, it's usually them." What a useless article, though I guess it was written for people that don't really know what ramsomware is.
Standard reporting now, something that isn't "us" must be Russia or China, no need to do any real investigation
Is a real investigation even possible? CIA leaks indicate they have tools to conceal the US origins of their malware and inject Chinese/Arabic/Russian etc text to fool forensic investigators
https://wikileaks.org/vault7/#Marble%20Framework
Well if a state couldn't conceal origin they aren't very good, but there are always markers..