Be on the lookout for attachments claiming to be W-9s. The attachment contains a malicious Microsoft OneNote document which will try to install Emotet malware.
Once Emotet is installed, the malware will steal emails to use in future reply-chain attacks, send further spam emails, and ultimately install other malware that provides initial access to other threats.
Takeaways
Sources: Bleeping Computer, Malwarebytes and Unit42