They are certainly identifiable from their work. State hackers are professionals and they work like other professionals do; they work 9-5 in their local time zone and they have modular implants with code reuse. Amateurs aren't like this.
That's basically the only argument I've heard so far - if a hacking activity happens between 06:00 UTC and 14:00 UTC then it must be the Russians, otherwise it's someone else. Doesn't sound like a very strong argument?
"Modular implants with code reuse" - sounds like exploit kits you can buy on hacking forums.
Security people seems to be of the militaristic type ofent, so I guess they add a slive of war mongering to it to to play ball.
Iran, North Korea and what not. Very convenient since it is not falsifiable in practice.