A new banking fraud operation tracked as REF6045 by Elastic Security Labs is targeting customers of Mexican banks, fintech platforms, payment processors, and cryptocurrency exchanges using ClickFix lures. The attack begins with fake CAPTCHA verification pages that trick victims into copying and pasting a malicious command into the Windows Run dialog, leading to the installation of a PowerShell toolkit called SCMBANKER. Some components of the malware date back to October 2025.
Once installed, SCMBANKER enables the operator to monitor banking sessions, lock the screen behind fake bank warnings, push victims toward live phone interaction (vishing), redirect browsers, replace account numbers copied to the clipboard, and deploy a commercial remote-access tool (Remote Utilities) for full takeover. The toolkit includes multiple PowerShell modules for self-update, C2 beaconing, clipboard hijacking of CLABE account numbers and card numbers, arbitrary PowerShell execution, banking activity monitoring, vishing overlays, and browser redirects to phishing landing pages.
Elastic’s findings stem from an operational security lapse in the REF6045 infrastructure, which exposed a ZIP archive containing the operation’s full web root directory. The malware uses a multi-stage infection process, including a fake Windows update screen to buy time, UAC privilege escalation, mouse locking, and persistence via the Windows Startup folder and Registry Run key. The code shows strong signs of AI assistance, likely prompted in Spanish and then manually obfuscated, with clean function names and heavy comments suggesting use of inline coding assistants like Copilot or Cursor.
The threat actor uses a live dashboard to monitor victims and engage only high-value targets, switching on browser redirects, vishing lockdowns, clipboard swaps, or full RAT access on demand. The researchers concluded that despite its crude construction, SCMBANKER already has real victims actively being targeted.
CVEs: CVE-2026-55200, CVE-2026-46817
Attack groups: REF6045
Malware: SCMBANKER, Remote Utilities
Companies: Elastic Security Labs, Microsoft
Products: Microsoft Edge, PowerShell, Remote Utilities
Original source: thehackernews.com