It is hard to defend against, unless you want a system that constantly prompts you for your password everytime you want to do something. Frequent password prompts is not really good for security either. Current mitigations really just slow down the attacks and gives you time to respond. If they are left alone they will manage to gather credentials over time.
https://github.com/gentilkiwi/mimikatz https://www.sans.org/reading-room/whitepapers/detection/mimi...
It's pretty complicated and requires server 2016 or windows 10. More info here - https://docs.microsoft.com/en-us/windows/security/identity-p...
How about running the OS in a Virtual Machine, that evaporates on exit and you get a new clean image on each invocation.
“All the King's horses and all the King's men couldn't put Humpty together again”
https://www.youtube.com/watch?v=tTl5Rl8cKy8
"Gig05 Pen Test War Stories Why my job is so easy and how you can make it harder Aaron Herndon"
It sounds like this attack was by a more sophisticated group that compromised some initial system in that way, and then somebody actually went in to explore and determine how to spread the compromise around further. It seems to be difficult indeed even for large and sophisticated companies to defend against these types of attacks. Since somebody, or a team of people, has to do most of the compromising manually, they naturally demand higher ransoms.
There are a lot of networks out there with fileshares configured far more permissively than they should be. Additionally, if the malware infects a machine that has cached domain admin credentials stored on it, it can use those to authenticate to the rest of the network and own the entire domain.
Yes, if best practice is followed, these tactics wouldn't work. Best practice is not always followed.
Privilege escalation: https://www.fuzzysecurity.com/tutorials/16.html
And if the company has everyone save their work on a shared network drive that lots of users have write access to, you don't even need to spread to other computers.
Plus of course, there are the classic means of spreading within a network - scan machines on the network for vulnerabilities, infect anything executable on shared drives, phishing e-mails that genuinely come from another employee's computer, keylog or brute force an admin password....