type: entity ยท created: 2026-07-11 ยท updated: 2026-07-11 ยท tags: [stealer, rat, cybercrime-group] ยท confidence: medium ยท affected_sectors: [finance, technology] ยท au_impact: false
SCMBANKER
SCMBANKER is a banking trojan uncovered by Elastic Security Labs in a campaign tracked as REF6045. The campaign targets Mexican banks, fintech firms, and cryptocurrency exchanges using ClickFix lures โ fake CAPTCHA pages that trick victims into running PowerShell commands.
Infection Chain
- Victim visits a compromised or malicious site
- Fake CAPTCHA page displayed ("ClickFix" lure) (raw/digests/Cyber-Digest-2026-07-09)
- Victim instructed to copy and run a PowerShell command to "verify they are human"
- PowerShell command downloads and executes the SCMBANKER toolkit
Capabilities
- Screen locking: Prevents victim from accessing their machine
- Browser redirection: Hijacks banking sessions
- RAT deployment: Installs remote access tools for full account takeover
- Multi-target: Targets Mexican banks, fintech firms, and crypto exchanges
Related Pages
- Redwing Maas โ Android-focused banking trojan (different platform)
- O Unc 066 โ Vishing-based credential theft (different technique, same goal)