A fraud operation tracked as REF6045 is targeting users across Mexico’s financial ecosystem with fake CAPTCHA ClickFix lures that trick victims into pasting a malicious command into the Windows Run dialog. The multi-stage infection chain installs a PowerShell-based toolkit called SCMBANKER, establishes persistence, and can optionally deploy Remote Utilities Host for full remote access. Researchers said the campaign has targeted banks, fintechs, payment processors, cryptocurrency exchanges, investment platforms, tax services, and telecom providers, and has likely been active since at least October 2025.
Once installed, SCMBANKER monitors banking sessions, captures screenshots and keystrokes, redirects browsers to phishing pages, displays fake bank warning overlays to push victims into vishing calls, and hijacks clipboard data including CLABE and payment card numbers. Elastic Security Labs said an operational security failure exposed parts of the attackers’ infrastructure, including open directories, a leaked web-root archive, and an unauthenticated file editor tied to 68.211.161[.]46, allowing investigators to recover extensive tooling. The recovered code also showed strong signs of AI-assisted development, likely drafted in Spanish and later manually obfuscated.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
On 2026-07-01, Elastic Security Labs published its analysis of REF6045, describing a Mexican banking fraud campaign using ClickFix-style fake CAPTCHA lures to deploy SCMBANKER. The report detailed capabilities including banking-session monitoring, screenshot capture, phishing redirection, clipboard hijacking, vishing overlays, and optional Remote Utilities deployment, and noted signs of AI-assisted development.
During the investigation, Elastic recovered extensive REF6045 tooling after the operators exposed open directories, a leaked web-root archive, an unauthenticated file editor, and an open directory at 68.211.161[.]46. The exposed infrastructure revealed details of the SCMBANKER infection chain and operator tooling.
Elastic Security Labs assessed that the PowerShell-based banking fraud toolkit SCMBANKER has likely been in use since at least October 2025 as part of the REF6045 operation targeting Mexico's financial ecosystem.
On 2026-06-18, Elastic Security Labs discovered the Mexican banking fraud operation tracked as REF6045 after observing suspicious bitsadmin activity. The investigation tied the activity to fake CAPTCHA ClickFix lures that install the SCMBANKER toolkit.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
4 references tracked. Mallory keeps watching after this page renders.
community.gurucul.com
Open sourcecybersecuritynews.com
Open sourcethehackernews.com
Open sourceelastic.co
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.