That doesn't actually say at all. Symantec's report has more detail but it still has gaps:
> The initial compromise of an organization involves the SocGholish framework, which is delivered to the victim in a zipped file via compromised legitimate websites.
> The zipped file contains malicious JavaScript, masquerading as a browser update.
So are people just like "this random website is trying to download a browser update, ok I'll unzip it and run it, even though I never normally have to do this". Seems plausible.
Then:
> Privilege escalation was performed using a publicly documented technique [there's a link] involving the Software Licensing User Interface tool (slui.exe), a Windows command line utility that is responsible for activating and updating the Windows operating system.
> The attackers used the Windows Management Instrumentation Command Line Utility (wmic.exe) to execute commands on remote computers, such as adding a new user or executing additional downloaded PowerShell scripts.
It's not really clear to me how local privilege escalation allows you to execute commands on remote computers though.