hacker-news · Crawled Jul 8, 2026

SCMBANKER Malware Uses ClickFix Lures to Target Mexican Banking Users

16 IoCs
Read original article ↗

AI Summary

A threat actor dubbed REF6045 is targeting Mexican banking and financial users through a malware toolkit named SCMBANKER, delivered via fake CAPTCHA lures. The attack uses social engineering to trick victims into executing a malicious command, leading to the installation of PowerShell-based malware that enables session monitoring, clipboard hijacking, browser redirection, and remote access. The operation shows signs of AI-assisted development, with poor operational security enabling researchers to recover infrastructure details. Victims are actively monitored and targeted based on financial activity, indicating ongoing live attacks.

AI-extracted · verify before operational use

Indicators of Compromise 16 extracted

Type Value Detail
IP 68[.]211[.]161[.]46 Details →
Domain fakeupdate[.]net Details →
Domain bancaporinternetbbmx[.]online Details →
Filename run.vbs Details →
Filename edifhjwe.ps1 Details →
Filename cliente.ps1 Details →
Filename avs.ps1 Details →
Filename clip.ps1 Details →
Filename clip2.ps1 Details →
Filename correr.ps1 Details →
Filename ini.ps1 Details →
Filename jujuzkt.ps1 Details →
Filename rotor2.ps1 Details →
Filename mensaje1.ps1 Details →
Filename jujuzkt2.ps1 Details →
Filename remo.ps1 Details →