The SCMBANKER campaign shows how ClickFix social engineering is being used to infect banking users by making them execute the malware themselves.

Victims are shown fake CAPTCHA verification pages that instruct them to copy and paste a command into the Windows Run dialog. That command launches a multi-stage PowerShell infection chain, displays a fake Windows update screen, and installs SCMBANKER on the system.

The malware is focused on Mexico’s financial ecosystem, including banks, fintech platforms, payment processors, and cryptocurrency exchanges. Its capabilities include banking-session monitoring, screenshot capture, keystroke logging, fake warning overlays, browser redirection, clipboard manipulation, and deployment of a remote-access tool for hands-on control.

SCMBANKER can watch for banking windows, replace CLABE account numbers and card numbers copied to the clipboard, redirect users to phishing pages, and push victims toward phone-based social engineering. So yes, apparently malware now comes with customer support, because criminals also discovered “assisted conversion.”

Organizations should train users never to paste commands from websites into Windows Run, PowerShell, Terminal, or command prompts. Security teams should monitor for suspicious PowerShell activity, fake update screens, bitsadmin usage, unusual startup persistence, clipboard manipulation, unauthorized remote-access tools, and connections to unfamiliar infrastructure.

The key lesson is that ClickFix attacks work because they turn the user into the execution engine. A fake verification screen should never be trusted when it asks the user to run commands manually. Real security checks do not require copying code into Windows.


A new banking fraudulent operation is targeting customers of Mexican banks, fintech, payment processors, and cryptocurrency exchanges using ClickFix lures. The activity cluster, tracked by Elastic Security Labs under the moniker REF6045, involves infecting victims through fake CAPTCHA verification pages that deceive them into running a malicious command that installs a PowerShell toolkit dubbed

Source: SCMBANKER Malware Uses ClickFix Lures to Target Mexican Banking Users via The Hacker News — published 08 Jul 2026.