Threats · 68 days ago
REF6045 turns a stolen click into a live fraud session. The attacker does not just drop a stealer and leave; the toolkit watches for banking use, changes what the victim sees, and can push the person into a phone handoff or remote-control step before the fraud is complete.
Elastic Security Labs says the campaign uses fake CAPTCHA ClickFix pages to make the victim run a command that installs SCMBANKER, a PowerShell toolkit with components in use since at least October 2025. Once installed, it can monitor banking sessions, capture screenshots, redirect the browser, swap copied account numbers, show fake bank warnings, and install Remote Utilities for full takeover. The operation targets Mexico’s financial ecosystem, including banks, fintechs, payment processors, crypto exchanges, investment platforms, SAT-facing services, and telecoms.
The risk is the live session itself. If controls assume theft ends at the login, this workflow keeps the attacker in the middle of the transaction and lets them steer the user in real time.
2 sources covering this story
SCMBANKER Malware Uses ClickFix Lures to Target Mexican Banking Users
SCMBANKER watches banking windows, captures screenshots, hijacks CLABE and card numbers, and can deploy Remote Utilities for hands-on access.
REF6045: Mexican banking fraud toolkit with signs of AI-assisted development — Elastic Security Labs
Elastic Security Labs breaks down SCMBANKER, a Mexican banking fraud toolkit delivered through ClickFix lures.
Part of the PlainSec briefing for 2026-07-07