As cited
Copy frozen at (site build).
threat intel
ClickFix to Cash-Out: Anatomy of a Mexican Banking-Fraud Toolkit
Elastic Security Labs discovered REF6045, a Mexican banking fraud operation that uses fake CAPTCHA pages to trick victims into installing SCMBANKER, a PowerShell toolkit designed for operator-assisted fraud. The human-controlled operation monitors infected machines to intercept banking sessions, manipulate credentials, and facilitate takeovers through techniques including screen locking, vishing overlays, clipboard manipulation, and remote access tool deployment. The operation's infrastructure exposed multiple OPSEC failures that revealed targeting of Mexican banks, fintechs, payment processors, and cryptocurrency exchanges.
Why it matters: Banks, fintechs, payment processors, and cryptocurrency exchanges operating in Mexico face immediate risk from this active banking fraud toolkit; security teams should implement detection for SCMBANKER PowerShell signatures, monitor for fake CAPTCHA delivery domains, and alert on bitsadmin downloads from suspicious servers.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
threat intel
ClickFix to Cash-Out: Anatomy of a Mexican Banking-Fraud Toolkit
Elastic Security Labs discovered REF6045, a Mexican banking fraud operation that uses fake CAPTCHA pages to trick victims into installing SCMBANKER, a PowerShell toolkit designed for operator-assisted fraud. The human-controlled operation monitors infected machines to intercept banking sessions, manipulate credentials, and facilitate takeovers through techniques including screen locking, vishing overlays, clipboard manipulation, and remote access tool deployment. The operation's infrastructure exposed multiple OPSEC failures that revealed targeting of Mexican banks, fintechs, payment processors, and cryptocurrency exchanges.
Why it matters: Banks, fintechs, payment processors, and cryptocurrency exchanges operating in Mexico face immediate risk from this active banking fraud toolkit; security teams should implement detection for SCMBANKER PowerShell signatures, monitor for fake CAPTCHA delivery domains, and alert on bitsadmin downloads from suspicious servers.
- Source published
- First seen by Cybersecurity Tracker