That bit, or in fact any bit of this warning apart maybe from the fairly generic advice about updatin, might not originate from Apple. It’s even possible that the detection of the malicious activity happened elsewhere, maybe the NSA, and Apple is simply the obvious communication channel through which to send the warning. Even if it was Apple’s systems that initially detected the suspicious activity (and my guess is that was the case) I would be very surprised if Apple hadn’t consulted with one or more government agencies such as the NSA before adding that “state-sponsored” attribution.