Have all of those IP addresses published as related to the hack been marked as dirty by Spamhaus e.a. before or after the hack - dates shown in the post are 20-Dec etc - after the hack was published.
As an example, here is the Spamhaus entry for one of the IPs. Notice the references to articles about the Sony hack: http://www.spamhaus.org/sbl/query/SBL242808
It's a bit like saying "the attackers used malware which made DNS queries via the IP address 8.8.8.8, which has been used by NK in the past" - if anyone were really building a case on that key evidence, they should prepare to be laughed at.