Explanation
Threat actors are using an Enovos phishing theme to collect email and LuxTrust credentials.
The phishing mail leads the user to believe that there are undue payments due to an error, and that they can expect an additional compensation of 200 € as a result of the caused inconvenience.
Clicking on “Se connecter” takes the user to the landing page, asking for e-mail credentials.
Afterwards, a similar message as in the email is shown (without the additional compensation of 200 €), and explaining the next steps:
- Click on the button ‘Suivant’
- Choose a bank.
- Confirm the transaction via LuxTrust In this step, the LuxTrust credentials are collected.
Example
![email_credentials]](/images/phishing/20231201-1/20231201-2.png)