SCMBANKER Malware Exploits ClickFix Lures for Mexican Banking Fraud
SCMBANKER is a PowerShell-based malware targeting Mexican banking users through deceptive ClickFix lures and fake CAPTCHA verification pages, utilizing AI-assisted tooling for banking session monitoring and credential theft. The malware employs multiple stages, including fake Windows updates and remote access capabilities, to compromise systems and redirect victims to phishing pages for financial fraud.
A new banking fraudulent operation is targeting customers of Mexican banks, fintech, payment processors, and cryptocurrency exchanges using ClickFix lures.
The activity cluster, tracked by Elastic Security Labs under the moniker REF6045, involves infecting victims through fake CAPTCHA verification pages that deceive them into running a malicious command that installs a PowerShell toolkit dubbed
*** END OF TRANSMISSION ***