REF6045 is a Mexico-focused banking fraud operation that uses ClickFix-style social engineering and active human operators to conduct real-time financial theft. The campaign targets users of Mexican banks and adjacent financial services, including fintech platforms, payment processors, cryptocurrency exchanges, investment services, tax-related services, and telecom providers. Victims are lured to fake verification or CAPTCHA pages and tricked into executing malicious commands that install SCMBANKER, a PowerShell-based toolkit used for operator-assisted account abuse and fraud. Unlike fully automated banking malware, REF6045 relies on hands-on monitoring and escalation. SCMBANKER watches for targeted banking or financial sessions, alerts an operator when a valuable session is detected, and enables the operator to decide when to intervene. Documented capabilities include screenshot capture, browser redirection to phishing pages, clipboard hijacking of banking and payment data, fake warning overlays used to support vishing or fraud workflows, and optional deployment of commercial remote-access software for full device takeover. Keylogging capability has also been observed in the toolkit. The infection chain uses staged scripts, privilege-elevation prompts, user-interface deception, and persistence mechanisms to maintain access. Observed tradecraft includes PowerShell-based payload delivery, use of bitsadmin to retrieve additional components, repeated elevation attempts, startup and Run-key persistence, and remote-access abuse for post-compromise control. Components of SCMBANKER date back to at least late 2025, and activity was observed in 2026. The operation appears financially motivated and is centered on fraud against Mexico’s financial ecosystem rather than espionage.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
14 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
3 malware families attributed to this actor across reporting.
65 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Mexican banking-fraud operation using fake CAPTCHA ClickFix-style lures to trick victims into executing commands that install the SCMBANKER PowerShell toolkit, enabling live banking-session interception, browser redirection, screen locking, clipboard manipulation, and follow-on remote-access tool deployment for full device takeover.
Operator-assisted banking fraud campaign using ClickFix-style fake verification pages to infect victims with the SCMBANKER toolkit, monitor banking activity, redirect sessions to phishing/vishing flows, hijack clipboard data, and optionally deploy remote access for hands-on fraud.
Conducting banking fraud operations targeting Mexico's financial ecosystem via ClickFix-style fake CAPTCHA lures that trick victims into executing malicious commands to install the SCMBANKER toolkit, enabling banking-session monitoring, phishing redirects, clipboard hijacking, vishing overlays, and optional RAT deployment.
Operator-assisted banking fraud campaign targeting Mexico via fake CAPTCHA/ClickFix lures that install the SCMBANKER PowerShell toolkit, enabling banking-session monitoring, screenshots, vishing overlays, phishing redirects, clipboard manipulation, and deployment of Remote Utilities for hands-on access.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.