Explanation
Threat actors are using compromised accounts of a Luxembourgish marketing and communication agency to collect Microsoft e-mail credentials. By using compromised accounts, the e-mail seems legitimate at first glance as it seems to originate from a known and trusted source. In reality, however, it is malicious.
The phishing mail leads the user to believe that there is a payment receipt to be reviewed.
By opening the attachment the user is taken to a fake Microsoft Excel login page, where they are asked for their username and password.
Example