I believe they've been GPA'ing GetThreadContext for a while, but not sure what they've been doing with it, if anything.
I noticed it yesterday, and it seemed to be acting strange. I noticed steam.exe called ZwGetContextThread (return address in kernel32.dll, so just GetThreadContext) at the same time as they did their RPM scans. However, the calls didn't seem to originate from the VAC module.