This activity is steps above a normal botnet or threat actor such as standard ransomware operators. Not only living off the land, but taking care to blend in to the device/environment, not just dropping a randomly named blob. They show a narrow focus of targeting, awareness for evasion, and skill at maintaining persistence. This level of sophistication is not normal, for normal incidents.
I bet sometimes they kick out bots that are competing for resources. Or at least scan for the other bots and carve it out, otherwise when there's two that's when they both start mining full blast, they each try to cash in the crypto keys on the computer before the other one does, and the user gets around to reinstalling the OS because his computer is unusable.
Based on the places where they were putting their threats I doubt mining was their goal. It sounds more that they were spelunking in case they wanted to ransomware and/or just wanting the information in a straightforward way. I wonder if also they were just using these servers as a foothold to attack something else. If you are mixing your traffic among an org's business presence it would be difficult to chase as a hop.