There are numerous incentives that, to me, make it not only reasonable but extraordinarily likely.
To me all this seems par for the course. There's nothing unusual about any of it. It's what you would expect. It's basically like distributed stochastic terrorism, indirectly/loosely driven by a more capable state actor with specific intent to establish deniability.
Not even plausible deniability. Just some convenient way to say 'Nyet! And we are VERY OFFENDED that you would even suggest such a thing!'.
Just the fortunes of war, really.
With ransomware criminals, “us” is the attacker, and “them” is everyone with a computer who might pay. Political boundaries don’t factor in to it at all. It is by nature an anonymous attack, hence the term “ransom”.
It is strange to me that almost all high-profile ransomware attacks that have been publicized in the US are claimed by the FBI to be Russian or Chinese. There are plenty of other countries with greedy criminals that know software, too.
Attacking things in a foreign jurisdiction is massively appealing from a "what will get me thrown in jail by my own government if things go wrong" perspective. You don't need any political loyalty for that calculation.
It's simply not true that political boundaries don't factor in. They're a massive part - most obviously, consider extradition or whether the attacker's government will cooperate with the US.
* I say many, but it's more like "it happens", but it feels important to point out.
There can only be one explanation: russian hackers operating with Putin's tacit approval. Us in the west should add this to the mounting pile of "evidence" supporting going into another cold war, because that will surely improve the entire situation. Attributing the unattributable to our preconceived enemies to escalate a conflict always ends well.
Snark aside, on a technical, factual level, this simply isn't evidence of origin, not even a little bit. "russian hackers" is such a tired punchline now that if I, being in the west, were to suddenly jump the fence after 3 decades and choose A Life Of Crime, using russian configuration file names, UTC+3 daytime operating hours, russian-hosted c&c IPs (or, better yet, russia-controlled but plausibly deniable ones like belarus or kazakhstan), and silly stuff like skipping infection of ru-locale machines would be obvious things I would be doing to fuel this existing narrative sailwind. It's utterly silly to think that this in any way suggests origin.