SCMBANKER is a PowerShell-based banking fraud toolkit used in the Mexico-focused fraud operation tracked by Elastic Security Labs as REF6045. Components date back to at least October 2025, and Elastic telemetry first observed an active infection in June 2026. The campaign infects victims through fake CAPTCHA or fake Google verification pages using the ClickFix technique, tricking users into copying and executing a malicious command from the Windows Run dialog. The first-stage command retrieves a script such as validation.txt and pipes it into cmd.exe, launches a fake Windows Update screen in Microsoft Edge kiosk mode as a distraction, repeatedly prompts for elevation, traps mouse movement, downloads additional payloads via bitsadmin into C:\Users\Public, establishes persistence via the Startup folder and an HKCU Run key using run.vbs, and forces a reboot.
SCMBANKER is designed for operator-assisted financial fraud rather than fully automated theft. After infection, it monitors visible window titles for targeted Mexican banking and financial-service sessions and alerts a human operator when a valuable session is detected. Reported capabilities include command-and-control beaconing, screenshot capture, browser redirection to phishing pages, clipboard hijacking of 18-digit CLABE account numbers and 16-digit card numbers, fake warning overlays and lock screens used in vishing workflows, and keylogging capability. In higher-value cases, the operators deploy the legitimate Remote Utilities Host remote-access tool for full hands-on control of the victim device.
The campaign targets Mexico’s financial ecosystem, including retail and business banks, fintech services, payment processors, cryptocurrency exchanges, investment platforms, SAT services, and telecom providers. Associated infrastructure and indicators mentioned in the content include domains ratonvaquero2026.online, monteviral2026.duckdns.org, osogransd.online, negratomasa2026.online, gestionmontelavaria2026.online, ssinvestigaciones.com, and bancaporinternetbbmx.online; IPs 68.211.161.46, 216.250.112.100, and 185.242.246.169; and SHA-256 hashes b30cb0aa977aacdab94d2ef503186c8f0b2fc10d7cf0d7c7c0ada70c127dc7e8, 554f1aefeb698995501751328c2f9fe93f02a680679fba3dd15f1ed93d46bf1b, ff3555154e91e42490cc722b6c7f3c4c91654b7ef53a35d0719ffb89accf1b27, 526287a40aad1b218228cdd1f459ad3b93f858585048347644d597c6ab19515a, and 685d29ce8a550feb3a9e1d1c5926ec5e927615cf34aab62c108a812a1eb6737c.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
PowerShell Backbone: The initial command installs SCMBANKER, a PowerShell toolkit using components from late 2025.
29 distinct techniques documented for this family, organized by ATT&CK tactic.
Malicious Entry Point: Victims are compromised via fake CAPTCHA pages that trick them into executing a harmful command.
Victims are infected through fake CAPTCHA pages that trick them into running a single command... At the web root ... we found a ClickFix fake-CAPTCHA flow that presented itself as a security verification page.
One such redirect destination, 'bancaporinternetbbmx[.]online,' contains a page-load Telegram notification script that harvests browser, device, and IP address details, and sends the information to a Telegram chat, alerting the operator that a redirected victim has reached the lure for follow-on attacks.
Elastic’s prevention guidance points to monitoring suspicious Run key changes, curl downloads piped into cmd, and DNS lookups tied to suspicious domains, alongside broader detection for script interpreters and remote access abuse.
PowerShell Backbone: The initial command installs SCMBANKER, a PowerShell toolkit using components from late 2025.
After the challenge, the page copies a command that pulls a first-stage script and pipes it into the Windows command shell.
Upon restart, the previous persistence mechanism via the Registry Run key triggers execution of the VBScript file ('run.vbs'). The Visual Basic Script serves as a master launcher to run several modules in parallel.
...then uses bitsadmin to download the rest of the toolkit into the public user directory.
The third script( remoto.ps1 ) ... imports a registry blob into HKLM\SOFTWARE\Usoris\Remote Utilities Host\Host\Parameters ... It also deletes the UninstallString
The page ... presented itself as a security verification page... using the lure text “Google Verificación Segura (Version 2025.5755)” ... Decoy strings “CIoudfIare” with capital-I homoglyphs
...then uses bitsadmin to download the rest of the toolkit into the public user directory.
Once running, the banking activity monitor checks all visible window titles every second. A match ... against any listed bank, fintech, payment processor, crypto exchange, brokerage, SAT, or telecom keywords causes the implant to POST an alert
cliente.ps1 collects a machine profile ... ip_local Get-NetIPAddress Internal network recon ... ip_public api.ipify.org External IP for geolocation and targeting
Every 30 seconds, cliente.ps1 collects a machine profile and performs an HTTP POST request to https://negratomasa2026[.]online/dashboard2/recData.php
key.ps1 fetches Telegram bot credentials... An observed redirect destination ... includes a page-load Telegram notification script ... sends the profile to a Telegram chat.
65 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A PowerShell-based banking-fraud toolkit used after fake CAPTCHA social engineering compromises victims. It supports live monitoring of infected devices, alerts operators when victims open targeted online banking sessions, and enables screen locking with fake warnings, browser redirection, clipboard account-number modification, and escalation to full device takeover via remote-access tools.
Operator-assisted banking fraud malware delivered via ClickFix-style fake Google verification/CAPTCHA pages. It monitors banking and financial sessions, alerts a human operator, captures screenshots, redirects browsers to phishing pages, hijacks clipboard data, displays vishing overlays/lock screens, and can deploy remote access tooling for hands-on fraud and account takeover.
A banking-focused PowerShell malware toolkit targeting Mexico's financial ecosystem. It monitors banking sessions, captures screenshots, logs keystrokes, displays fake bank warning overlays for vishing, redirects browsers to phishing pages, manipulates clipboard contents to reroute transactions, establishes persistence, and can deploy Remote Utilities for full remote access.
Operator-assisted banking fraud malware targeting Mexico. It monitors banking sessions, captures screenshots, displays vishing overlays, redirects browsers to phishing pages, hijacks clipboard contents for CLABE and card-number substitution, supports keylogging, persists via Run key/startup folder, and can install Remote Utilities for full remote access.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.