Explanation
Threat actors are using a Post.lu phishing theme to collect credit card information and Luxtrust credentials.
The phishing mail leads the user to believe that a new package was delivered, and by clicking on the link the user is redirected to the phishing landing page.
When the victim clicked on the link, they are redirected to a fake credit card form. Once this information is provided, they are then redirected to a fake Luxtrust form, where the ultimate goal is to collect Luxtrust token one-time-passwords and credentials.
Example