hacker-news · Crawled Jul 8, 2026
SCMBANKER Malware Uses ClickFix Lures to Target Mexican Banking Users
16 IoCs
Read original article ↗
AI Summary
A threat actor dubbed REF6045 is targeting Mexican banking and financial users through a malware toolkit named SCMBANKER, delivered via fake CAPTCHA lures. The attack uses social engineering to trick victims into executing a malicious command, leading to the installation of PowerShell-based malware that enables session monitoring, clipboard hijacking, browser redirection, and remote access. The operation shows signs of AI-assisted development, with poor operational security enabling researchers to recover infrastructure details. Victims are actively monitored and targeted based on financial activity, indicating ongoing live attacks.
AI-extracted · verify before operational use
Indicators of Compromise 16 extracted
| Type | Value | Detail |
|---|---|---|
| IP | 68[.]211[.]161[.]46 | Details → |
| Domain | fakeupdate[.]net | Details → |
| Domain | bancaporinternetbbmx[.]online | Details → |
| Filename | run.vbs | Details → |
| Filename | edifhjwe.ps1 | Details → |
| Filename | cliente.ps1 | Details → |
| Filename | avs.ps1 | Details → |
| Filename | clip.ps1 | Details → |
| Filename | clip2.ps1 | Details → |
| Filename | correr.ps1 | Details → |
| Filename | ini.ps1 | Details → |
| Filename | jujuzkt.ps1 | Details → |
| Filename | rotor2.ps1 | Details → |
| Filename | mensaje1.ps1 | Details → |
| Filename | jujuzkt2.ps1 | Details → |
| Filename | remo.ps1 | Details → |