More info on EG: https://securelist.com/files/2015/02/Equation_group_question...
The dump contains many tools; but the ones used in this attack are two exploits for vulnerabilities in Windows SMB (Server Message Block, a file sharing protocol) implementation. Microsoft patched this in March, but as we all know, many systems remain unpatched. The vulnerabilities allowed for remote code execution.
Practical exploit info: https://www.exploit-db.com/docs/41896.pdf
The two exploits, EternalBlue and EternalChampion targets respectively SMBv2 and SMBv1. That's not how the ransomware gets inside the network in the first place though, that is done by a user executing a file received via email, or downloaded from a received URL. But, through these two exploits, once inside, it can spread through the network (subnet) worm-like. Actually, the ransomware first checks for the existence of the backdoor (also from the same dump of tools) called DoublePulsar. If the ransomware does not find it to be implanted, it will use one of the two aforementioned exploits, based on which ports and protocols it makes a connection to.
The DoublePulsar backdoor is installed on at least 400,000+ systems worldwide.
You can read more about it here: https://countercept.com/our-thinking/analyzing-the-doublepul...