Fake CAPTCHA Fraud Tools Stay Inside Live Banking Sessions

REF6045 turns a stolen click into a live fraud session. The attacker does not just drop a stealer and leave; the toolkit watches for banking use, changes what the victim sees, and can push the person into a phone handoff or remote-control step before the fraud is complete. Elastic Security Labs says the campaign uses fake CAPTCHA ClickFix pages to make the victim run a command that installs SCMBANKER, a PowerShell toolkit with components in use since at least October 2025. Once installed, it can monitor banking sessions, capture screenshots, redirect the browser, swap copied account numbers, show fake bank warnings, and install Remote Utilities for full takeover. The operation targets Mexico’s financial ecosystem, including banks, fintechs, payment processors, crypto exchanges, investment platforms, SAT-facing services, and telecoms. The risk is the live session itself. If controls assume theft ends at the login, this workflow keeps the attacker in the middle of the transaction and lets them steer the user in real time.

Part of the PlainSec briefing for 2026-07-07

Sources