According to CrowdStrike, this actor is using TinyLoader and TinyPOS, potentially buying access through Dridex infections.
No exploited CVEs have been attributed to this threat actor yet.