A sophisticated threat actor known as REF6045 is targeting Mexican financial institutions using the SCMBANKER malware toolkit, which leverages fake CAPTCHA lures and AI-generated scripts to compromise users.
Key Points
- The REF6045 group uses "ClickFix" lures, masquerading as CAPTCHA challenges to trick victims into executing malicious PowerShell commands.
- SCMBANKER malware monitors banking sessions, hijacks clipboards to reroute transactions, and deploys remote-access tools for full system takeovers.
- Researchers at Elastic Security Labs discovered the operation after an operational security lapse exposed the group's entire web root directory.
- The toolkit includes specialized modules for vishing, browser redirection, and monitoring window titles for specific Mexican banks and cryptocurrency exchanges.
- Analysis indicates the attackers utilized large language models to generate significant portions of the malicious code, resulting in a mix of clean and obfuscated scripts.