Home ยท Wiki ยท Entities & Threat Actors
type: entity ยท created: 2026-07-11 ยท updated: 2026-07-11 ยท tags: [stealer, rat, cybercrime-group] ยท confidence: medium ยท affected_sectors: [finance, technology] ยท au_impact: false

SCMBANKER

SCMBANKER is a banking trojan uncovered by Elastic Security Labs in a campaign tracked as REF6045. The campaign targets Mexican banks, fintech firms, and cryptocurrency exchanges using ClickFix lures โ€” fake CAPTCHA pages that trick victims into running PowerShell commands.

Infection Chain

  1. Victim visits a compromised or malicious site
  2. Fake CAPTCHA page displayed ("ClickFix" lure) (raw/digests/Cyber-Digest-2026-07-09)
  3. Victim instructed to copy and run a PowerShell command to "verify they are human"
  4. PowerShell command downloads and executes the SCMBANKER toolkit

Capabilities

  • Screen locking: Prevents victim from accessing their machine
  • Browser redirection: Hijacks banking sessions
  • RAT deployment: Installs remote access tools for full account takeover
  • Multi-target: Targets Mexican banks, fintech firms, and crypto exchanges

Related Pages

  • Redwing Maas โ€” Android-focused banking trojan (different platform)
  • O Unc 066 โ€” Vishing-based credential theft (different technique, same goal)