It looks like this was not caused by a 0-day, it is apparently using EternalBlue as execution vector plus another (already fixed) vulnerability for lateral movement.
It also appears to be using common Windows lateral movement techniques based on credential stealing (namely WMI and PsExec), in addition to EternalBlue.