Explanation
Threat actors are impersonating a journalist of a Luxembourgish newspaper to collect credentials.
The attack starts with an email that tells the targeted user they have a secured message waiting for them.
By clicking on the link “Read the PDF”, the user is redirected to a document disguised as a “NEW EFT PAYMENT Notification”.
In the final step, the victim is redirected to a fake phishing page, where the ultimate goal is to collect credentials.
Example
 


