SCMBANKER Malware Uses ClickFix Lures to Target Mexican Banking Users
ID: 9a460d6a-5e21-5113-bff4-fc8107d997b2
STIX ID: report--9a460d6a-5e21-5113-bff4-fc8107d997b2
Feed Name: The Hacker News
REF6045 (SCMBANKER) is an ongoing financially motivated campaign targeting Mexican banks, fintechs, payment processors, and cryptocurrency exchanges using fake CAPTCHA lures that trick victims into running a command to install a multi-stage PowerShell toolkit; capabilities include banking-session monitoring, clipboard swapping to redirect payments, vishing overlays, browser redirects to phishing pages, and optional deployment of a commercial remote-access tool, with Elastic recovering the operation's webroot and evidence of live victims.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
