Explanation
Threat actors are using a Post.lu theme to collect email and credit card credentials.
This time, the phishing mail leads the user to believe that the delivery address is incomplete and needs to be updated.
By clicking on the link ‘‘MyPost’’ the user is redirected to the first phishing landing page, which asks for personal information and to choose a bank.
Once this information is provided, a form requesting credit card information is shown.
Example