Just received a bunch of cryptocurrency phising spam from their domain. Definitely pretty interesting, and they were actually fairly well done with a proper link text, but an incorrect link.
The Metamask spamming campaign primarily use their own list -- compromised credentials are mainly used to get SMTP access and then spam away until they get caught.