Explanation
Threat actors are using a Guichet.lu phishing theme to collect Luxtrust credentials.
The phishing mail leads the user to believe that they are due to a tax refund, and by clicking on the link the user is first redirected to a fake Guichet.lu page.
On this page, the victim has to choose a bank: Bilnet, Spuerkees, ING, eboo banque, Raiffeisen, BGL BNP Paribas and Other.
Once they have chosen their bank, they are redirected to a fake Luxtrust form, shown using a theme for the chosen bank, where the goal is to collect Luxtrust credentials.
Example