Explanation
Threat actors are trying to collect Luxtrust credentials and OTP token.
The phishing mail leads the user to believe that their electronic identity certificate will expire soon (e.g. 2 days). By scanning the QR-code (quick response code) the user is first redirected to a fake Luxtrust page.
On this page, the victim first has to click the button “Renouveler le certificat”, after which they have to choose a bank: Spuerkeess, Eboo banque, Bilnet or ING.
Once they have chosen their bank, they are redirected to a fake Luxtrust form using the chosen bank as theme. The goal is to collect the Luxtrust credentials.
Example