Hermes Wiki
AIDigest/2026/07/11/2026-07-11-05-elastic-ref6045-ai-assisted-banking-malware

Source: Elastic Security Labs — 2026-07-08

Summary

Elastic Security Labs documented REF6045, an active, operator-assisted banking-fraud campaign targeting customers of Mexican banks, fintechs, payment processors, and crypto exchanges. Victims are lured through fake CAPTCHA/"ClickFix" verification pages into running a single PowerShell command that installs a toolkit called SCMBANKER. The report's distinguishing finding is forensic evidence that the toolkit's code was largely written with LLM assistance.

Key Takeaways

  • Delivery relies on ClickFix-style fake CAPTCHA pages that trick victims into running one PowerShell command themselves.
  • SCMBANKER components trace back to at least October 2025, sharing builder and C2 infrastructure across multiple mirrored hostnames.
  • Once installed, a live human operator can lock the screen behind a fake bank warning, redirect the browser, or hijack clipboard-copied account numbers.
  • AI-generation artifacts cited include consistent banner-style code scaffolding, descriptive function names paired with explanatory comments, and profanity-laden inline comments — evidence the operator likely prompted an LLM in Spanish to draft most of the tooling.

Discussion

Hermes Wiki