Trend Micro telemetry shows the threat actors behind the campaign expanding botnet to other countries that include Australia, Taiwan, Vietnam, Hong Kong, and India. The primary malware propagation involves using the weak credentials to gain access to the computer that connected with the same network. It uses a number of techniques that includes EternalBlue, Powershell, pass-the-hash technique, Windows admin tools, and brute force to infect windows machine and to drop a Monero miner. The malware leverages weak passwords in. databases, targets legacy software that companies may still be using,. exploits unpatched vulnerabilities, and installs using the Windows startup folder and the Windows task scheduler”]
Source: https://gbhackers.com/miner-malware-multiple-propagation/

