A new Mexican banking fraud operation tracked as REF6045 is taking a highly hands-on approach to stealing financial data.
Instead of relying on automated scripts, a human operator actively monitors infected machines using a PowerShell toolkit named SCMBANKER. The attack begins with fake CAPTCHA pages that trick victims into copying and pasting a malicious command.
Once installed, the operator gains extensive control to intercept banking sessions, lock screens with fake warnings, manipulate clipboards, and deploy commercial remote-access tools.
The infection chain starts with a ClickFix delivery method. Victims encounter a fake security verification page asking them to complete an image challenge, often in Spanish.
This page instructs them to paste a specific command into the Windows Run dialog. Executing this command triggers a hidden Windows batch script disguised as a text file.
ClickFix Powers Mexican Fraud
To buy time during the installation, the script launches Microsoft Edge in full-screen kiosk mode, displaying a fake Windows Update screen.
It then traps the user’s mouse in a single pixel to prevent interference. Behind the scenes, the malware downloads the SCMBANKER toolkit in pieces using Windows’ native background transfer tool.

Despite the severe threat SCMBANKER poses, the REF6045 operators demonstrate surprisingly poor operational security and coding practices.
Researchers discovered that the infrastructure supporting this malware was left completely exposed. The attackers enabled directory listings, allowing anyone to download the raw PowerShell scripts.
Even worse, their command-and-control server featured an unauthenticated file editor, leaving live targeting configuration files completely unprotected.
Elastic said, an analysis of the SCMBANKER source code reveals heavy reliance on artificial intelligence. The scripts contain undeniable hallmarks of large language model generation, likely prompted by the threat actor in Spanish.
The code features highly structured banner comments separating distinct script sections. Clean function names mix abruptly with hand-shortened variables and leftover generation artifacts.

Base64-encoded API names sit directly next to comments explaining exactly what they decode to. Aggressive profanity appears in specific modules, likely used to bypass AI safety filters for sensitive tools.
This operation highlights a growing trend in the threat landscape: actors with limited technical skills using AI assistants to generate functional, multi-stage malware.
While REF6045 relies on crude infrastructure and copy-pasted code, the human-driven approach combined with SCMBANKER’s invasive tools makes it a highly effective banking fraud campaign.
Indicators of Compromise (IOCs)
| IOC Type | Value | Description |
|---|---|---|
| IPv4 | 68.211.161[.]46 | ClickFix / file host |
| IPv4 | 216.250.112[.]100 | ClickFix / file host |
| IPv4 | 185.242.246[.]169 | REF6045 C2 |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Follow us on Google News , LinkedIn and X to Get More Instant Updates. Set Cyberpress as a Preferred Source in Google.