Recommended reading: Storm-0978 (DEV-0978; also referred to as RomCom) attacks reveal financial and espionage motives,
by Microsoft Threat Intelligence

https://www.microsoft.com/en-us/security/blog/2023/07/11/storm-0978-attacks-reveal-financial-and-espionage-motives/

Storm-0978 attacks reveal financial and espionage motives | Microsoft Security Blog

Microsoft has identified a phishing campaign conducted by the threat actor tracked as Storm-0978 targeting defense and government entities in Europe and North America. The campaign involved the abuse of CVE-2023-36884, which included a zero-day remote code execution vulnerability exploited via Microsoft Word documents.

Microsoft Security Blog