Majority of information about Windows malware I get from big computer security companies' research blogs like:
https://www.trendmicro.com/en_us/research.html
https://www.proofpoint.com/us/blog
https://research.checkpoint.com/
https://blog.talosintelligence.com/
https://www.welivesecurity.com/en/
Microsoft also got good security research blog: https://www.microsoft.com/en-us/security/blog/
Majority of the research combes down to researching malware's capabilities regarding malware persistence, anti-VM techniques and anti-debugging techniques.
Here is for example good compilation of malware's anti-debugging and anti-VM techniques:
Zero days account for very small amount of exploitation in comparison and by definition are unpatched so I think the commenter was right to point out the basics.
Immutable snapshots/offline backups help with those.
Or there is a service running in the context of a service user domain account. Or the password of the local administrator account is identical on all systems, which was very common before LAPS became a thing.
Yes, if you do everything perfectly and always go by best practices, none of this should be relevant, but most people aren't doing everything perfectly all of the time.
To access any of these things, you need local admin permissions. Then you can reuse them to log on to other systems.
'just' harden the system is not easy.
But installing something like a vmware guest driver is easy, as even a non-technical user can do it following some basic instructions.
What? This is an entirely separate concern. If you have a Russian input method installed, malware will terminate to avoid legal repercussions.