please excuse my ignorance but it looks like most incidents are from romania and germany, am i wrong? why is he highlighting china?
<Insert usual suspect here> high up can be read just as "many internet users there, whose PC or other device is infected with malware that tries to spread itself".
As the article states: originating device can be silly IoT device like a router, TV, printer, Ring-style doorbell, etc etc etc. In fact, chance of random IoT device being vulnerable and/or been 'recruited' in a botnet, may be bigger than the same with random PC / tablet etc. Many IoT devices are junk that rarely see firmware updates (if any).
That being said: attributing those attacks to Chinese actors based on IP falls a little short. Proxychains exist and are used.