CyberSecurityBoardThreat Intel · CVEs · Products
Attack Groups

REF6045: Banking Fraud Operation Targeting Mexican Financial Institutions

July 8, 2026

REF6045 is a threat actor cluster tracked by Elastic Security Labs that uses ClickFix lures to infect victims with the SCMBANKER malware. The operation targets customers of Mexican banks, fintech, payment processors, and cryptocurrency exchanges. The group leverages AI-assisted code development and a multi-stage infection process involving fake CAPTCHA pages, Windows Run dialog execution, and persistence mechanisms. The operator uses a live dashboard to monitor victims and engage high-value targets with browser redirects, vishing, clipboard hijacking, and remote access tools.