The common narrative in discounting any involvement of North Korea is that they're too famished and uneducated to perform such an operation. Your angle is that the attack isn't sophisticated enough?
The evolving story is that a single IT worker with significant right grants was targeted by the group, and once that single user was exploited, their privileges were used to compromise the network. If you have the privileges of a superuser, your attack doesn't need to be sophisticated.
And ultimately this is exactly how I would expect these sort of attacks to go, especially when hitting targets in free and open nations. Why go through the trouble and effort of trying to winnow in from the outside when you can just exploit the kink or vulnerabilities of individual people -- who you can now discover via LinkedIn -- and then work your magic from the "inside". Sending out a group policy to disable all security software is a couple of lines. This "virus" seemed to be a simple efficiency measure, as with those rights they could do pretty much everything, though mass malice would probably be too labor intensive minus some helpful tools.
The defense against this is of course that even admins should have limits on their access and flags on their activities. Of course, the admins are the ones who normally implement this, so...