Recommended reading: Storm-0978 (DEV-0978; also referred to as RomCom) attacks reveal financial and espionage motives,
by Microsoft Threat Intelligence
Storm-0978 attacks reveal financial and espionage motives | Microsoft Security Blog
Microsoft has identified a phishing campaign conducted by the threat actor tracked as Storm-0978 targeting defense and government entities in Europe and North America. The campaign involved the abuse of CVE-2023-36884, which included a zero-day remote code execution vulnerability exploited via Microsoft Word documents.