logo

SCMBANKER Malware Uses ClickFix Lures to Target Mexican Banking Users

ID: 9a460d6a-5e21-5113-bff4-fc8107d997b2

STIX ID: report--9a460d6a-5e21-5113-bff4-fc8107d997b2

Feed Name: The Hacker News

Threat Score
75/100

Date Published: 2026-07-08

Date Updated: 2026-07-18

Author: [email protected] (The Hacker News)

...
...

REF6045 (SCMBANKER) is an ongoing financially motivated campaign targeting Mexican banks, fintechs, payment processors, and cryptocurrency exchanges using fake CAPTCHA lures that trick victims into running a command to install a multi-stage PowerShell toolkit; capabilities include banking-session monitoring, clipboard swapping to redirect payments, vishing overlays, browser redirects to phishing pages, and optional deployment of a commercial remote-access tool, with Elastic recovering the operation's webroot and evidence of live victims.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.