There’s a new banking malware operation targeting Mexico. Elastic Security Labs tracks it as REF6045. The tool: a PowerShell toolkit called SCMBANKER. Some components date back to October 2025.
The infection chain starts with a fake CAPTCHA page. Victims get a Google reCAPTCHA-style challenge asking them to pick images with fire hydrants. Once they pass (or think they do), they’re told to copy and paste a command into the Windows Run dialog.
That command triggers a batch script. First thing it does: launch Microsoft Edge in kiosk mode pointing to fakeupdate.net, a well-known red-team site that shows a fake Windows Update screen. It’s a distraction — buys time for the malware to install in the background.
The script checks if it has admin rights. If not, it pops a UAC prompt every 20 seconds. Annoying enough that most people will click “Yes” just to make it stop. Once it gets elevated privileges, it locks mouse movement. The fake update screen keeps the victim sitting there while bitsadmin downloads the full toolkit.
Once installed, SCMBANKER can monitor banking sessions, grab screenshots, overlay fake security warnings, redirect browsers, and even replace copied account numbers with attacker-controlled ones. For full takeover, it can deploy a commercial RAT.
Elastic got a look at the operator’s infrastructure through an operational security lapse — an open directory that spilled the whole web root. The scripts show clear signs of AI assistance. Clean function names and explanatory comments sit next to hand-obfuscated variables. The researchers suspect Copilot or Cursor was used, prompted in Spanish.
The toolkit includes modules for self-update, C2 beaconing, clipboard hijacking (for CLABE account numbers and card numbers), keystroke logging, vishing overlays, and browser redirects. One redirect destination used Telegram notifications to alert operators when a victim lands on a phishing page.
“Crude as it is, SCMBANKER already has real victims,” Elastic concluded.
Victims of Mexican financial institutions — banks, fintechs, payment processors, crypto exchanges — should be on alert.
