< BACK TO NEWS
negativeSYS.SOURCE: The Hacker News2026-07-08T18:22:15+05:30

SCMBANKER Malware Exploits ClickFix Lures for Mexican Banking Fraud

SCMBANKER is a PowerShell-based malware targeting Mexican banking users through deceptive ClickFix lures and fake CAPTCHA verification pages, utilizing AI-assisted tooling for banking session monitoring and credential theft. The malware employs multiple stages, including fake Windows updates and remote access capabilities, to compromise systems and redirect victims to phishing pages for financial fraud.

A new banking fraudulent operation is targeting customers of Mexican banks, fintech, payment processors, and cryptocurrency exchanges using ClickFix lures.

The activity cluster, tracked by Elastic Security Labs under the moniker REF6045, involves infecting victims through fake CAPTCHA verification pages that deceive them into running a malicious command that installs a PowerShell toolkit dubbed

Read original article

*** END OF TRANSMISSION ***