by The_Un1que » 17 May 2017 09:09
Correct what Thoryk is saying.
SPAM mails, mail attachments including a free Dubai ticket, internet sites adds, fake antivirus and mailware programs....all of these might be one of having this ransomware inside.
The biggest problem here was that you can have only one person to be infected and then it was easily spread out over the network using a backdoor, or let's call it a fail inside Windows systems having SMB 1.0 still active.
Latest March 2017 security monthly included this fix for the SMB, but if you have your environment having at least one server or computer which isn't properly patched you can be at risk to have your file shares, and other devices infected.
Brati asked about backup options. Yes, they might help, but imagine to have an enterprise environment that has a file share (like 20TB of files) infected...this take days to get back all the files back to normal. Also, mostly user computers are not backup daily or weekly, so all private storage on the hard drive can be forgotten (in most cases).