REF6045 is a Mexican banking fraud operation tracked by Elastic Security Labs. It targets customers of Mexican banks and broader financial services in Mexico, including retail and business banking portals, fintech services, payment processors, cryptocurrency exchanges, investment platforms, SAT services, and telecom providers. The operation uses fake Google verification or CAPTCHA pages and the ClickFix social-engineering technique to trick victims into copying and executing a malicious command, typically via the Windows Run dialog. That infection chain installs SCMBANKER, a PowerShell-based banking fraud toolkit whose components date back to at least October 2025. REF6045 is notable for being operator-assisted rather than fully automated. Human operators monitor infected devices and receive live alerts when victims open targeted banking or financial sessions, then decide when to escalate. SCMBANKER monitors visible window titles for targeted institutions, captures screenshots, includes keylogging capability, redirects active browser sessions to phishing pages, displays fake warning overlays to support vishing workflows, and hijacks clipboard contents including CLABE account numbers and card numbers. The toolkit also establishes persistence via the Windows Startup folder and Registry Run keys, uses bitsadmin to download additional payloads, and can deploy the legitimate Remote Utilities Host product for full remote access and hands-on takeover. Observed infrastructure and delivery patterns in the reporting include fake CAPTCHA delivery sites, phishing pages, and command-and-control infrastructure. Known aliases directly mentioned in the content are limited to REF6045. A closely associated malware/toolkit name is SCMBANKER.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
14 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
3 malware families attributed to this actor across reporting.
65 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Mexican banking-fraud operation using fake CAPTCHA ClickFix-style lures to trick victims into executing commands that install the SCMBANKER PowerShell toolkit, enabling live banking-session interception, browser redirection, screen locking, clipboard manipulation, and follow-on remote-access tool deployment for full device takeover.
Operator-assisted banking fraud campaign using ClickFix-style fake verification pages to infect victims with the SCMBANKER toolkit, monitor banking activity, redirect sessions to phishing/vishing flows, hijack clipboard data, and optionally deploy remote access for hands-on fraud.
Conducting banking fraud operations targeting Mexico's financial ecosystem via ClickFix-style fake CAPTCHA lures that trick victims into executing malicious commands to install the SCMBANKER toolkit, enabling banking-session monitoring, phishing redirects, clipboard hijacking, vishing overlays, and optional RAT deployment.
Operator-assisted banking fraud campaign targeting Mexico via fake CAPTCHA/ClickFix lures that install the SCMBANKER PowerShell toolkit, enabling banking-session monitoring, screenshots, vishing overlays, phishing redirects, clipboard manipulation, and deployment of Remote Utilities for hands-on access.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.