I don't think there's any nation state level actors or fancy zero days in play here, just ordinary organized crime. This appears to be very effective and profitable.
Most corporate networks are very bad when it comes to administration practices and credential hygiene. I'm talking about Active Directory of course, which is the identity and management backbone of most every corporate network. However, to be accurate, this isn't a problem with AD as a technology itself - it can be made very secure - but how it's deployed and used in practice. Of course, you could argue that a technology is bad if deploying it securely requires arcane knowledge and isn't the default configuration... However, the same underlying principles or weaknesses exist in the underpinning technologies or concepts themselves and are not AD specific.
Ideally, Active Directory is the identity management backbone of your entire corporate network. Identities and devices are centrally managed through it. Ideally, access to every single server, workstation and application is managed through it.
Compromise the identity management backbone and you compromise everything that it controls access to, i.e. the entire network and all business data. Doesn't matter whether it's AD or MIT Kerberos or whatever.
In practice, this issue is Windows- and Active Directory specific, but mostly because AD is the most widely deployed directory service by far and Windows machines tend to be domain joined for effective management.
But to be clear, Linux would be vulnerable to this in exactly the same way if they were configured similarly, which they're often not. But you could have MIT Kerberos etc. running to centrally manage access to all of your Linux assets - compromise it and you compromise all assets it manages access to.
In AD, there's a group called Domain Admins which grants unrestricted administrative access to every single workstation, server and identity in the directory. In today's security conscious world, that concept is very much a blast from the past, but I digress...
On most networks, practices are generally very lax and the number of Domain Admins and the use of such accounts thereof vastly exceeds the minimal scope they should be used in. Admins log in to standard workstations with them etc. putting the accounts/credentials at risk of theft.
On most networks, it's fairly trivial to move laterally after the initial foothold and to capture Domain Admin credentials (because they're scattered all over the place), after which the entire network is compromised and it's game over.
I've seen it happen in the span of about 12 minutes from initial compromise via the internet to malware being deployed to thousands of endpoints at once through AD. No actual vulnerabilities needed, just bad (network) administrative practices.