Source: Elastic Security Labs — 2026-07-08
Summary
Elastic Security Labs documented REF6045, an active, operator-assisted banking-fraud campaign targeting customers of Mexican banks, fintechs, payment processors, and crypto exchanges. Victims are lured through fake CAPTCHA/"ClickFix" verification pages into running a single PowerShell command that installs a toolkit called SCMBANKER. The report's distinguishing finding is forensic evidence that the toolkit's code was largely written with LLM assistance.
Key Takeaways
- Delivery relies on ClickFix-style fake CAPTCHA pages that trick victims into running one PowerShell command themselves.
- SCMBANKER components trace back to at least October 2025, sharing builder and C2 infrastructure across multiple mirrored hostnames.
- Once installed, a live human operator can lock the screen behind a fake bank warning, redirect the browser, or hijack clipboard-copied account numbers.
- AI-generation artifacts cited include consistent banner-style code scaffolding, descriptive function names paired with explanatory comments, and profanity-laden inline comments — evidence the operator likely prompted an LLM in Spanish to draft most of the tooling.