SCMBANKER Malware Uses ClickFix Lures to Target Mexican Banking Users
ClickFix lures are being used by a new banking fraud scheme to target clients of Mexican banks, fintech, payment processors, and cryptocurrency exchanges.
The activity cluster, which Elastic Security Labs is monitoring under the name REF6045, entails tricking users into executing a malicious command that installs a PowerShell toolkit known as SCMBANKER by using phony CAPTCHA verification sites. The malware's components go all the way back to October 2025.
According to security experts Jia Yu Chan and Salim Bitam, once installed, the operator can observe when a victim begins a banking session, lock the screen behind a fictitious bank warning, guide the victim toward live phone interaction, reroute the browser, or modify account numbers copied to the clipboard. They can even use a com...

