They seem to have actual people that contact accounts/leads and their contexts from somewhere in India, and those people share spam accounts. Initially they try to sell you some tickets to an analytics and cyber security conference at first, but then they try to contact C-staff as soon as you start reacting.
The C-staff members then get trapped into the selling and audit game, so they offer free pentests / IT audits and "cyber security software" that can fix the problems (duh).
I created a honeypot with a fake domain and a fake company that doesn't exist, with emails that cannot be guessed blindly and with an email server that doesn't list its account names (and account names are not bruteforceable and neither guessable). Zero links on the internet, domain isn't even google-able.
Once I trapped them with private linkedin profiles and the people of whitehall media contacted the fake accounts, the spam arrived in masses. I'm not talking about 10 or 20 a day but in the thousands per day. And their network of hosts that they operate is _huge_.
My current guess is that they abuse administrative access to their customer's servers (the analytics/cybersecurity/IT-security forefront) to install their malware and send spam on their customers' behalf without them even knowing about it. We contacted our customers afterwards and asked all others whether or not they had contact to them; and if so that they start to double-check on their server infrastructure because it was very likely that they got infiltrated.