From what Microsoft said DEV-0537 is opportunistic; they are Purchasing credentials and session tokens from criminal underground forums
Paying employees at targeted organizations (or suppliers/business partners) for access to credentials and MFA approval
Searching public code repositories for exposed credentials
and they are exploiting publicly known exploits in order to infiltrate organizations.
Like somebody already mentioned they are similar to LulzSec in a way they are partially financially motivated, partially hacktivist and partially bragging around but all in all they are doing it for the "lulz".