Explanation
Threat actors are using a Guichet.lu phishing theme to collect Luxtrust credentials.
The phishing mail leads the user to believe that they are due a tax refund. By scanning the QR-code (quick response code) the user is first redirected to a fake Guichet.lu page.
On this page, the victim has to choose a bank: Bilnet, Spuerkees, ING, eboo banque, Raiffeisen, BGL BNP Paribas and Other.
Once they have chosen their bank, they are redirected to a fake Luxtrust form, shown using a theme for the chosen bank, where the goal is to collect Luxtrust credentials.
Example