CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

SCMBANKER Malware Uses ClickFix Lures to Target Mexican Banking Users

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 2172

As cited

Copy frozen at (site build).

threat intel

SCMBANKER Malware Uses ClickFix Lures to Target Mexican Banking Users

A threat actor tracked as REF6045 is targeting Mexican banking customers, fintech users, and cryptocurrency exchange clients using ClickFix lures that impersonate CAPTCHA verification pages. The attack chain tricks victims into executing malicious PowerShell commands that install a banking malware toolkit called SCMBANKER. This represents an emerging fraud operation against financial services and payment infrastructure in Mexico.

Why it matters: Financial services organizations, fintech firms, and cryptocurrency exchanges operating in Mexico need to alert customers about fake CAPTCHA lures and implement endpoint detection for suspicious PowerShell execution, as compromised banking credentials can lead to unauthorized fund transfers and account takeovers.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary