apparently, Sigop DDoS attack is possible now, because the Sigops per block limit is too high.
Why isn't anyone using the attack then?

Always assume that if a malicious vector exists then someone will try and exploit it
From memory the closest we've come to that to date was that single transaction 1MB block from f2pool that took nodes up to 25 seconds to validate. It is possible to make it much worse, but newer versions of bitcoind (and probably faster node CPUs) would have brought that down. Rusty at the time estimated it could still take up to 11 seconds with 1MB:
https://rusty.ozlabs.org/?p=522So yeah it has been used... possibly unwittingly at the time.