AUTO-UPDATED

SCMBANKER Malware Uses ClickFix Lures to Target Mexican Banking Users

A sophisticated threat actor known as REF6045 is targeting Mexican financial institutions using the SCMBANKER malware toolkit, which leverages fake CAPTCHA lures and AI-generated scripts to compromise users.

Key Points

  • The REF6045 group uses "ClickFix" lures, masquerading as CAPTCHA challenges to trick victims into executing malicious PowerShell commands.
  • SCMBANKER malware monitors banking sessions, hijacks clipboards to reroute transactions, and deploys remote-access tools for full system takeovers.
  • Researchers at Elastic Security Labs discovered the operation after an operational security lapse exposed the group's entire web root directory.
  • The toolkit includes specialized modules for vishing, browser redirection, and monitoring window titles for specific Mexican banks and cryptocurrency exchanges.
  • Analysis indicates the attackers utilized large language models to generate significant portions of the malicious code, resulting in a mix of clean and obfuscated scripts.

Why it Matters

This campaign highlights the growing trend of threat actors using generative AI to rapidly develop and deploy complex malware toolkits against specific regional financial sectors. By automating the creation of phishing and monitoring tools, attackers can scale their operations while maintaining a persistent presence on victim devices to facilitate fraud.
Internet Published by info@thehackernews.com (The Hacker News)
Read original