See: https://arstechnica.com/security/2017/05/an-nsa-derived-rans...
Once it's infected a host, the SMB scanning for vulnerable hosts is launched and secondary infections begin with no further user action required.
So far it seems an hypothesis and nobody has shown such an email attachment, which is strange considering all the systems out there which save and archive attachments. Especially hospitals and gov't sites saves it all.
http://researchcenter.paloaltonetworks.com/2017/05/palo-alto...
It continues to be a very common attack method and I'd be surprised if it wasn't leveraged again.
If so, you wouldn't need a very high phish:total infected hosts ratio to explain the numbers. And given that whoever was originally phished didn't know it was an illegitimate email... not betting we'll see many examples of the initial vector.
The original authors first released it with their own bitcoin address. It then spreads p2p around the world wherever it can to front-facing PCs.
Then 3rd-party spearfishers are sending it to corporate networks with their own bitcoin address so they can get the credit for getting past/through firewalls.
If someone was really clever they could change the Tor addresses it talks to for command & control and write their own complete replacement backend, but at that point it seems like you'd be looking at people capable enough to just write their own malware from scratch anyway...
Some level of trust would be involved.
I think the spearfishing industry and the malware writing industry aren't one and the same. The former is the marketing department, the latter is the tech department.