Explanation
Threat actors are using a Post.lu theme to collect email credentials.
As seen previously, the phishing mail leads the user to believe that a new document from Post.lu arrived.
By opening the attachment and clicking on the link -Mise à jour- the user is redirected to the phishing landing page.
On the landing page the user is asked to enter their Post.lu email credentials, after which the user
is redirected to the authentic Post Webmail.
Example