The REF6045 banking-fraud operation is targeting Mexico’s financial ecosystem with ClickFix-style fake CAPTCHA pages that deceive victims into running commands that install the SCMBANKER PowerShell toolkit. The campaign targets banks, fintechs, payment processors, cryptocurrency and investment platforms, the SAT tax authority, and telecommunications services; researchers found components dating to at least October 2025.
SCMBANKER monitors banking activity, captures screenshots, intercepts CLABE and payment-card data copied to the clipboard, redirects browsers to phishing pages, and displays fake bank-warning overlays to support vishing. The toolkit can also deploy Remote Utilities Host for persistent remote access. Exposed directories, archived web content, and unauthenticated C2 configuration editors revealed shared SCM-branded infrastructure and targeting configurations; Elastic assessed that the crude but operational PowerShell tooling was likely substantially generated with LLM assistance before light obfuscation.

Get the infrastructure and lures behind it.
3 events from the most recent confirmed update back to the earliest known activity.
Elastic telemetry detected suspicious bitsadmin downloads associated with REF6045 activity.
Elastic Security Labs observed the REF6045 operator-assisted banking-fraud operation targeting Mexico's financial ecosystem with ClickFix lures and the SCMBANKER PowerShell toolkit.
VirusTotal evidence indicates that earlier versions of SCMBANKER toolkit components had been in use since at least October 2025.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 68 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Get the infrastructure, lures, and IOCs behind this campaign, ready to push into your email and identity stack.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.