A new and highly sophisticated cyberattack has targeted customers of banks, fintech companies, payment providers, and cryptocurrency exchanges in Mexico. Researchers at Elastic Security Labs have uncovered a campaign dubbed REF6045, which uses the ClickFix to trick victims into installing a powerful banking malware called SCMBANKER.

The trap starts with a fake CAPTCHA
The attack is based on a social engineering technique that is gaining traction. The victim visits a page that looks like a legitimate CAPTCHA security check, where they are asked to complete a supposed verification process.
See also: ClickFix: Analysis of 3,000 payloads reveals API-driven malware
After the fake CAPTCHA is completed, instructions appear prompting the user to copy and execute a command in the Windows Run window . In doing so, the victim unwittingly activates the malware, bypassing several security mechanisms .
Fake Windows update to save time
Immediately after executing the command, a screen Windows update, giving the impression that the computer is performing a normal update. However, in the background, the malware installs itself, gains administrator privileges, and creates mechanisms to remain permanently on the system even after a reboot.
Researchers explain that attackers use this method to keep the user busy while the installation of all the tools needed for the attack is completed.
What can SCMBANKER do?
SCMBANKER is designed exclusively for attacks on financial institutions and has an impressively large number of functions.
Among other things, it can:
- monitors when the user logs into e-banking,
- records keystrokes,
- takes screenshots,
- automatically replaces bank account numbers copied to the clipboard,
- redirects the user to fake banking websites,
- displays fake security warnings that urge the victim to call the perpetrators' phone numbers (vishing),
- and installs remote access software, allowing attackers to gain complete control of the computer.
In practice, cybercriminals can monitor a victim's banking transactions in real time and intervene only when they detect a significant money transfer.
See also: ClickFix campaigns expand malware distribution with new loaders and fake updates

Artificial intelligence at the service of cybercriminals
One of Elastic's most interesting findings is that a significant portion of the malware appears to have been created with the help of large language models (LLMs), such as tools like Copilot or Cursor.
The researchers identified comments in the code and function names that strongly resemble AI-generated code, while the creators then proceeded to manually hide certain elements to make it more difficult to analyze.
The incident shows that artificial intelligence is now being used not only by security experts, but also by cybercriminals who want to develop new attacks more quickly.
See also: LeakNet Ransomware group uses ClickFix techniques
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
What users should watch out for
This particular campaign is currently targeting organizations and users in Mexico, but experts warn that the ClickFix can easily be adapted to other countries.
The basic rule is simple: no legitimate website will ever ask you to copy and execute commands in the Windows Run window to complete a CAPTCHA check or verification process.
At the same time, using up-to-date security software, enabling multi-factor authentication (MFA), and being alert to unusual messages or pages are the most effective protection measures against such attacks. Researchers estimate that although SCMBANKER is not technically the most sophisticated malware, it has already caused real fraud incidents, proving that the success of a cyberattack often depends more on user deception than on the complexity of the malware itself.
