The entry points are "whatever works".
Typically:
* Password spraying from previous data leaks
* Good old-fashioned fishing
* Bugs in anything that's common in enterprises, exposed to the Internet and not patched fast enough, including MS Exchange, various security/VPN products, vcenter, you name it. All of these had pretty critical pre-auth bugs exposed just this year
* malicious browser plugins
* malicious O365 apps
... and so on.