Explanation
Threat actors are trying to collect credit card information, Luxtrust credentials and OTP token.
The phishing mail leads the user to believe that their electronic identity certificate will expire soon (e.g. 2 days), and by clicking on the link the user is redirected to the phishing landing page.
The first landing page presents an input form to collect credit card information.
Once that information is provided,
the web page redirects the victim to another form where the goal is to collect Luxtrust token one-time-passwords and credentials.
Example