There never will be any solid evidence - given the way that AV software works I doubt that any state actor would leave any crumbs of evidence - in many cases all the AV software would have to do is "fail" to detect an approved Trojan arriving via some method. It would be hard to "detect" that.

