As cited
Copy frozen at (site build).
threat intel
SCMBANKER Malware Uses ClickFix Lures to Target Mexican Banking Users
A threat actor tracked as REF6045 is targeting Mexican banking customers, fintech users, and cryptocurrency exchange clients using ClickFix lures that impersonate CAPTCHA verification pages. The attack chain tricks victims into executing malicious PowerShell commands that install a banking malware toolkit called SCMBANKER. This represents an emerging fraud operation against financial services and payment infrastructure in Mexico.
Why it matters: Financial services organizations, fintech firms, and cryptocurrency exchanges operating in Mexico need to alert customers about fake CAPTCHA lures and implement endpoint detection for suspicious PowerShell execution, as compromised banking credentials can lead to unauthorized fund transfers and account takeovers.
- Source published
- First seen by Cybersecurity Tracker