I have a strong suspicion that the 3 letter agencies are tied to ransomware attacks, since they don't seem to be doing anything about it. And it is a nice way to raise $$.
I'd also bet that any groups arrested for ransomware attacks are competition to the clown agencies.
I’ve been seeing files with Russian words in malicious payloads which I believe is an easy way to disguise its origin. Oh look, it must be a Russian hacker since it has a Cyrillic script. It’s a pretty huge ecosystem but would not be shocked to find out the clowns are more involved than most realize
That's almost always a giveaway. Someone smart enough to breach corporate security (yeah, some companies are easy to hack, but not all), leaves part of their home address in the code. Especially with all the code and language converters available online.