Talos has been concerned about the proliferation of malware via unpatched network vulnerabilities. Unlike WannaCry, Nyetya does not appear to contain an external scanning component. We have observed no use of email or Office documents as a delivery mechanism for this malware. We believe infections are associated with software update systems for a Ukrainian tax accounting package called MeDoc. The malware requires user credentials to spread itself laterally via the PsExec and WMIC vectors (which are detailed in the “Malware Functionality” section)”]
Source: https://blog.talosintelligence.com/2017/06/worldwide-ransomware-variant.html

