Note this is partially covered in MITRE Technique T1068 BYOVD "Bring Your Own Vulnerable Driver". If the driver is not already loaded, it necessary to be local admin to be able to load it.
Yep, this kind of thing is typically used as an EDR-killer when you want to touch protected processes and perform lateral movement. It’s interesting to see it used here as part of initial access tooling.
I also mostly seen it as EDR/AV killer. A bit overkill as initial access, but thats part of the joke of the article