CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

ClickFix to Cash-Out: Anatomy of a Mexican Banking-Fraud Toolkit

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 2113

As cited

Copy frozen at (site build).

threat intel

ClickFix to Cash-Out: Anatomy of a Mexican Banking-Fraud Toolkit

Elastic Security Labs discovered REF6045, a Mexican banking fraud operation that uses fake CAPTCHA pages to trick victims into installing SCMBANKER, a PowerShell toolkit designed for operator-assisted fraud. The human-controlled operation monitors infected machines to intercept banking sessions, manipulate credentials, and facilitate takeovers through techniques including screen locking, vishing overlays, clipboard manipulation, and remote access tool deployment. The operation's infrastructure exposed multiple OPSEC failures that revealed targeting of Mexican banks, fintechs, payment processors, and cryptocurrency exchanges.

Why it matters: Banks, fintechs, payment processors, and cryptocurrency exchanges operating in Mexico face immediate risk from this active banking fraud toolkit; security teams should implement detection for SCMBANKER PowerShell signatures, monitor for fake CAPTCHA delivery domains, and alert on bitsadmin downloads from suspicious servers.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

ClickFix to Cash-Out: Anatomy of a Mexican Banking-Fraud Toolkit

Elastic Security Labs discovered REF6045, a Mexican banking fraud operation that uses fake CAPTCHA pages to trick victims into installing SCMBANKER, a PowerShell toolkit designed for operator-assisted fraud. The human-controlled operation monitors infected machines to intercept banking sessions, manipulate credentials, and facilitate takeovers through techniques including screen locking, vishing overlays, clipboard manipulation, and remote access tool deployment. The operation's infrastructure exposed multiple OPSEC failures that revealed targeting of Mexican banks, fintechs, payment processors, and cryptocurrency exchanges.

Why it matters: Banks, fintechs, payment processors, and cryptocurrency exchanges operating in Mexico face immediate risk from this active banking fraud toolkit; security teams should implement detection for SCMBANKER PowerShell signatures, monitor for fake CAPTCHA delivery domains, and alert on bitsadmin downloads from suspicious servers.

VendorsMicrosoftGoogle
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary