SCMBANKER is a PowerShell-based banking fraud toolkit used in a Mexico-focused operator-assisted campaign tracked as REF6045. The malware is delivered through ClickFix-style fake CAPTCHA or verification pages that trick victims into copying and executing a malicious command on Windows systems. The infection chain uses staged scripts, deceptive update screens, and privilege-elevation prompts to install the toolkit, establish persistence, and prepare the host for ongoing fraud operations.
SCMBANKER is designed to support real-time financial theft rather than fully automated credential harvesting alone. After installation, it monitors active window titles for targeted banking, fintech, payment, cryptocurrency, investment, tax, and telecom services associated with Mexico’s financial ecosystem. When a valuable session is detected, the malware alerts a human operator, enabling hands-on decision-making and escalation against selected victims. Documented capabilities include screenshot capture, clipboard hijacking to replace payment details such as bank account and card numbers, browser redirection to phishing pages, fake warning overlays used to facilitate vishing-style fraud, and optional deployment of commercial remote-access software for full device takeover. Keylogging capability has also been documented in the toolkit.
The malware establishes persistence through Windows autorun mechanisms and uses multiple PowerShell modules launched in parallel to manage command-and-control, banking-session monitoring, fraud workflows, and remote-access enablement. Reported tradecraft includes use of background transfer utilities for payload retrieval, fake Windows update decoys to distract victims during installation, and user-interface interference to keep victims engaged while the toolkit is deployed. Components associated with SCMBANKER date back to at least October 2025, with active infections observed in 2026. The campaign has been linked to active targeting of Mexican retail and business banking customers, fintech users, payment processors, cryptocurrency exchanges, investment platforms, tax-related services, and telecom providers.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
PowerShell Backbone: The initial command installs SCMBANKER, a PowerShell toolkit using components from late 2025.
29 distinct techniques documented for this family, organized by ATT&CK tactic.
Malicious Entry Point: Victims are compromised via fake CAPTCHA pages that trick them into executing a harmful command.
Victims are infected through fake CAPTCHA pages that trick them into running a single command... At the web root ... we found a ClickFix fake-CAPTCHA flow that presented itself as a security verification page.
One such redirect destination, 'bancaporinternetbbmx[.]online,' contains a page-load Telegram notification script that harvests browser, device, and IP address details, and sends the information to a Telegram chat, alerting the operator that a redirected victim has reached the lure for follow-on attacks.
Elastic’s prevention guidance points to monitoring suspicious Run key changes, curl downloads piped into cmd, and DNS lookups tied to suspicious domains, alongside broader detection for script interpreters and remote access abuse.
PowerShell Backbone: The initial command installs SCMBANKER, a PowerShell toolkit using components from late 2025.
After the challenge, the page copies a command that pulls a first-stage script and pipes it into the Windows command shell.
Upon restart, the previous persistence mechanism via the Registry Run key triggers execution of the VBScript file ('run.vbs'). The Visual Basic Script serves as a master launcher to run several modules in parallel.
...then uses bitsadmin to download the rest of the toolkit into the public user directory.
The third script( remoto.ps1 ) ... imports a registry blob into HKLM\SOFTWARE\Usoris\Remote Utilities Host\Host\Parameters ... It also deletes the UninstallString
The page ... presented itself as a security verification page... using the lure text “Google Verificación Segura (Version 2025.5755)” ... Decoy strings “CIoudfIare” with capital-I homoglyphs
...then uses bitsadmin to download the rest of the toolkit into the public user directory.
Once running, the banking activity monitor checks all visible window titles every second. A match ... against any listed bank, fintech, payment processor, crypto exchange, brokerage, SAT, or telecom keywords causes the implant to POST an alert
cliente.ps1 collects a machine profile ... ip_local Get-NetIPAddress Internal network recon ... ip_public api.ipify.org External IP for geolocation and targeting
Every 30 seconds, cliente.ps1 collects a machine profile and performs an HTTP POST request to https://negratomasa2026[.]online/dashboard2/recData.php
key.ps1 fetches Telegram bot credentials... An observed redirect destination ... includes a page-load Telegram notification script ... sends the profile to a Telegram chat.
65 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named as another malware family distributed via ClickFix in the broader threat landscape.
Referenced as a prior ClickFix-related banking malware example for comparison, not as part of the TELEPUZ infection chain described here.
SCMBANKER is only mentioned in passing as another malware/threat previously propagated via ClickFix.
A PowerShell-based banking-fraud toolkit used after fake CAPTCHA social engineering compromises victims. It supports live monitoring of infected devices, alerts operators when victims open targeted online banking sessions, and enables screen locking with fake warnings, browser redirection, clipboard account-number modification, and escalation to full device takeover via remote-access tools.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.