A Patched remote code execution Microsoft Office Vulnerability ( CVE-2017-11882) has been abusing again and using it for spreading a variety of Malware such as FAREIT, Ursnif and a Keylogger Loki info stealer that is used for stealing Crypto wallet password. The initial level of infection spreading via spam email campaign that contains a malicious attachment file that claimed as a payment copy with order confirmation body content. Body content is written in Korean language and given fake warning as Please check if your PC may be infected by a virus or malicious codes”]
Source: https://gbhackers.com/office-vulnerability-keylogger/

