HomeSecuritySCMBANKER malware uses ClickFix and targets bank users

SCMBANKER malware uses ClickFix and targets banking users

A new and highly sophisticated cyberattack has targeted customers of banks, fintech companies, payment providers, and cryptocurrency exchanges in Mexico. Researchers at Elastic Security Labs have uncovered a campaign dubbed REF6045, which uses the ClickFix to trick victims into installing a powerful banking malware called SCMBANKER.

Article Image: SCMBANKER Malware Uses ClickFix Lures to Target Mexican Banking Users

The trap starts with a fake CAPTCHA

The attack is based on a social engineering technique that is gaining traction. The victim visits a page that looks like a legitimate CAPTCHA security check, where they are asked to complete a supposed verification process.

See also: ClickFix: Analysis of 3,000 payloads reveals API-driven malware

After the fake CAPTCHA is completed, instructions appear prompting the user to copy and execute a command in the Windows Run window . In doing so, the victim unwittingly activates the malware, bypassing several security mechanisms .

Fake Windows update to save time

Immediately after executing the command, a screen Windows update, giving the impression that the computer is performing a normal update. However, in the background, the malware installs itself, gains administrator privileges, and creates mechanisms to remain permanently on the system even after a reboot.

Researchers explain that attackers use this method to keep the user busy while the installation of all the tools needed for the attack is completed.

What can SCMBANKER do?

SCMBANKER is designed exclusively for attacks on financial institutions and has an impressively large number of functions.

Among other things, it can:

  • monitors when the user logs into e-banking,
  • records keystrokes,
  • takes screenshots,
  • automatically replaces bank account numbers copied to the clipboard,
  • redirects the user to fake banking websites,
  • displays fake security warnings that urge the victim to call the perpetrators' phone numbers (vishing),
  • and installs remote access software, allowing attackers to gain complete control of the computer.

In practice, cybercriminals can monitor a victim's banking transactions in real time and intervene only when they detect a significant money transfer.

See also: ClickFix campaigns expand malware distribution with new loaders and fake updates

SCMBANKER malware uses ClickFix and targets banking users

Artificial intelligence at the service of cybercriminals

One of Elastic's most interesting findings is that a significant portion of the malware appears to have been created with the help of large language models (LLMs), such as tools like Copilot or Cursor.

The researchers identified comments in the code and function names that strongly resemble AI-generated code, while the creators then proceeded to manually hide certain elements to make it more difficult to analyze.

The incident shows that artificial intelligence is now being used not only by security experts, but also by cybercriminals who want to develop new attacks more quickly.

See also: LeakNet Ransomware group uses ClickFix techniques

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

What users should watch out for

This particular campaign is currently targeting organizations and users in Mexico, but experts warn that the ClickFix can easily be adapted to other countries.

The basic rule is simple: no legitimate website will ever ask you to copy and execute commands in the Windows Run window to complete a CAPTCHA check or verification process.

At the same time, using up-to-date security software, enabling multi-factor authentication (MFA), and being alert to unusual messages or pages are the most effective protection measures against such attacks. Researchers estimate that although SCMBANKER is not technically the most sophisticated malware, it has already caused real fraud incidents, proving that the success of a cyberattack often depends more on user deception than on the complexity of the malware itself.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS