LIVE · cybersecurity feed
Live wire
banking trojanhigh

ClickFix to Cash-Out: Anatomy of a Mexican Banking-Fraud Toolkit

A sophisticated banking fraud operation, dubbed REF6045, utilizes a PowerShell toolkit named SCMBANKER, delivered via fake CAPTCHA pages. Unlike automated attacks, this operation is manually controlled, allowing operators to monitor victim banking sessions, deploy fake warnings, and manipulate browser activity. The toolkit also facilitates the installation of commercial remote access tools for full system takeover. Researchers discovered the operation through exposed directories and archives, revealing the use of AI-generated scripts and operator misconfigurations.

zeroday.news · 24d ago

A Mexican banking fraud campaign, identified as REF6045, is being actively managed by human operators who monitor infected systems and direct malicious activities. The initial infection vector involves deceptive CAPTCHA pages that trick users into executing a command, which then installs the SCMBANKER PowerShell toolkit. This toolkit, with components dating back to at least October 2025, provides operators with a comprehensive suite of tools for financial fraud.

Once SCMBANKER is deployed, operators can observe when a victim initiates a banking session. They can then lock the victim's screen with a fake bank warning, push the user towards live phone support, redirect their web browser, or even replace copied bank account numbers with their own. For complete control, the operation can also deploy commercial remote access tools.

Key aspects of the REF6045 operation include the adaptation of ClickFix delivery methods to facilitate operator-assisted banking fraud. Fake verification pages are used to stage the SCMBANKER toolkit, which offers a full fraud workflow. This includes monitoring banking activity, capturing screenshots, presenting vishing overlays, executing phishing redirects, manipulating clipboard data, and installing remote access tools.

The SCMBANKER toolkit specifically targets Mexico's financial ecosystem, encompassing retail and business banking portals, fintech companies, payment processors, cryptocurrency exchanges, investment platforms, tax authorities (SAT), and telecommunications services. The operation's tooling and targeting logic were exposed due to operator security oversights, such as open directories, a leaked web archive, and an unauthenticated file editor.

Analysis of the scripts revealed a significant number of AI-generated artifacts, suggesting the operator leveraged large language models (LLMs) in their development. Elastic Security Labs detected the operation on June 18, 2026, when telemetry indicated a host downloading suspicious PowerShell scripts from an exposed directory. Retrieving an archive from the same server provided a more complete view of the operation's web root.

The infection chain begins with a ClickFix fake CAPTCHA page, which presents an image challenge before instructing the victim to run a command. This command downloads a batch script disguised as a validation file. The script then initiates a series of malicious actions, including launching a fake Windows Update screen in Microsoft Edge's kiosk mode to distract the victim.

To ensure elevated privileges, the malware checks for administrator rights and, if absent, prompts the user with a social-engineered message to update their system, repeatedly relaunching itself with administrative privileges until the User Account Control (UAC) prompt is accepted. Once elevated, the mouse cursor is confined to a tiny area on the screen, preventing user interaction and further facilitating the background download of the SCMBANKER toolkit.

Malicious scripts and binaries are downloaded individually via bitsadmin from an exposed file server to a public directory. Persistence is established through the Windows Registry's Run key and the Startup folder, ensuring the toolkit launches on subsequent logons. The operation also includes a mechanism to force a reboot, which then triggers the persistence routines.

The SCMBANKER toolkit's master launcher is a VBScript that initiates various modules in parallel. These modules handle tasks such as process rotation, delayed execution of monitoring and redirect scripts, C2 communication, remote access tool installation, clipboard hijacking for account numbers, and arbitrary PowerShell command execution. An invisible cursor utility is also deployed to further hinder user interaction.

banking trojanpowershellmalware analysismexicoclickfix
ShareXLinkedInWhatsAppFacebook

More News

view all →
vulnerability

Coldcard Hardware Wallet Flaw Linked to $70 Million Bitcoin Theft in 41 Minutes

An attacker drained 1,196 Bitcoin addresses in 41 minutes on July 30, taking 1,082.65 BTC worth about $70.2 million at the time. Galaxy Research mapped the sweep and tied it to a firmware flaw in Coldcard, the Bitcoin-only hardware wallet made by Canadian firm Coinkite. A March 2021 firmware integration error routed seed generation to a deterministic software pseudorandom number generator (PRNG

vulnerabilitycritical

Rails patches critical Active Storage flaw with RCE potential

A critical vulnerability in the Active Storage framework can allow an unauthenticated attacker to read arbitrary files from a Rails application, and potentially escalate to remote code execution (RCE). [...]

malware

Russian Hackers Hijack Hotel Wi-Fi to Steal Microsoft 365 Tokens

Microsoft says Russian hackers hijacked hotel Wi-Fi portals to spread malware and steal Microsoft 365 tokens from travelers. Microsoft Threat Intelligence disclosed CaptiveCrunch, a campaign it attributes to Storm-2945, an operational sub-cluster of Midnight Blizzard, the Russian SVR-linked group also known as APT29 and Cozy Bear. Since early May 2026, Storm-2945 has been manipulating DNS […]

CVE-2026-48449critical

Adobe fixed a maximum-severity vulnerability flaw in Campaign Classic

Adobe fixed a maximum severity vulnerability in Campaign Classic that could let attackers run code remotely without user interaction. Adobe has addressed a critical vulnerability, tracked as CVE-2026-48449 (CVSS score of 10.0), in Adobe Campaign Classic, the company’s enterprise marketing automation platform. The flaw is caused by incorrect authorization and could allow attackers to execute […]

security

Balance Theory Raises $19 Million to Help Enterprises Manage Cybersecurity Investments

The funding round was led by SYN Ventures, with participation from existing investors DataTribe and TEDCO. The post Balance Theory Raises $19 Million to Help Enterprises Manage Cybersecurity Investments appeared first on SecurityWeek.

vulnerabilitycritical

Ruby on Rails Patches Critical Vulnerability

The flaw can be exploited by unauthenticated attackers to read arbitrary files and potentially achieve remote code execution (RCE). The post Ruby on Rails Patches Critical Vulnerability appeared first on SecurityWeek.