Explanation
The objective of this phishing campaign is to gather personal information and LuxTrust credentials.
The domain used in this campaign mimics the appearance of the official LuxTrust site and claims that suspicious activity has been detected on the LuxTrust certificate.
It tries to scare the user by stating that they might be hacked and leads them to ‘verify’ their account.
This alleged ‘Identity Validation’ collects detailed information about the user and even goes as far as to request the answers to the security questions of the user’s bank account.
Finally, after all the details are provided, a message is displayed promising a callback from a LuxTrust assistant.
This might indicate further steps of this campaign being performed over the phone.
All the described steps take place on pages under the malicious domain ’luxtrust[.]support’ .
Example


