SCMBANKER Malware Uses ClickFix Lures to Target Mexican Banking Users 21%

By Ravie Lakshmanan13%

7/8/2026, 12:52:00 PM

BS Summary: This article contains 18 faulty reasoning types, including Overconfidence Bias, Negativity Bias, and Post Hoc (False Cause), with Unattributed Quote as the most egregious example at 24.5% saturation with 228 hits. Analysis detected 1,330 faulty-reasoning hits from 930 analyzed words, generating a BS Score of 34.8% and a BS Rank of 21% (16,857 of 21,112 articles). This article is better (less manipulative) than 79.80% of the article peer group.

A new banking fraudulent operation is targeting customers of Mexican banks, fintech, payment processors, and cryptocurrency exchanges using ClickFix lures. 
The activity cluster, tracked by Elastic Security Labs under the moniker REF6045, involves infecting victims through fake CAPTCHA verification pages that deceive them into running a malicious command that installs a PowerShell toolkit dubbed SCMBANKER. 
Some components of the malware date back to October 2025. 
"Once installed, the operator can see when a victim opens a banking session, lock the screen behind a fake bank warning, push the victims towards live phone interaction, redirect the browser, or replace account numbers copied to the clipboard," security researchers Jia Yu Chan and Salim Bitam said. 
"For a full takeover, they can also deploy a commercial remote-access tool." 
SCMBANKER is specifically designed to go after Mexico's financial ecosystem, with evidence pointing to the use of a large language model (LLM) to develop a huge chunk of the tooling. 
The toolkit supports a wide range of capabilities, including banking-session monitoring, screenshot capture, vishing overlays, phishing redirects, clipboard manipulation, and Remote Utilities installation. 
Elastic's findings stem from an operational security lapse in the REF6045 infrastructure, which made it possible to retrieve a ZIP archive containing the operation's full web root directory from an open directory located at "68.211.161[.] 
46." 
The starting point is a fake CAPTCHA check that disguises itself as a security verification page, urging potential victims to solve a Google reCAPTCHA-like challenge to identify images containing a fire hydrant. 
Once the step is complete, they are presented with instructions to copy and paste a malicious command into the Windows Run dialog. 
This, in turn, triggers the execution of a batch script that's responsible for installing the malware through a multi-stage process, starting with a bogus Windows update screen. 
"The batch script immediately launches Microsoft Edge in kiosk mode pointing to fakeupdate[.]net, a well-known pentesting/red team site that renders a fake Windows Update screen," Elastic said. 
"This distraction buys time for the script to fully execute." 
In the next stage, the script checks if it's running as admin, and if not, launches a Windows User Account Control (UAC) prompt every 20 seconds, effectively nudging the victim towards clicking "Yes" on the consent dialog. 
As soon as it gains elevated privileges, it locks mouse movement. 
This behavior, combined with the fake Windows update screen, forces the victim to stay, giving the malware ample time to download the complete toolset in the background using the bitsadmin tool from the same directory. 
After SCMBANKER components are downloaded onto the compromised host, it sets up persistence using the Windows Startup folder and a Registry Run key, following which it programmatically sends an F11 keypress event to exit full screen and initiate a "Ctrl+W" keypress sequence to close the fake Windows update tab. 
"However, this approach only works in a standard full-screen browser window, not in kiosk mode," Elastic said. 
"It then forces a reboot with the shutdown /r /t 02 command and switches. 
Upon restart, the previous persistence mechanism via the Registry Run key triggers execution of the VBScript file ('run.vbs')." 
The Visual Basic Script serves as a master launcher to run several modules in parallel - 
* edifhjwe.ps1, for toolkit self-update 
* cliente.ps1, for command-and-control (C2) beacon and implant control 
* avs.ps1, for downloading the Remote Utilities RAT installer to facilitate hands-on access to a victim's machine 
* clip.ps1 and clip2.ps1, for CLABE account number and card number, clipboard hijack to reroute transactions 
* correr.ps1, for arbitrary PowerShell execution 
* ini.ps1, a launcher for "jujuzkt.ps1," a banking activity monitor that checks all visible window titles every second for matches against a list of Mexican financial institutions and, if a match is found, takes screenshots and logs keystrokes 
* rotor2.ps1, a wrapper for "mensaje1.ps1," a vishing engine that serves fake overlays with security warnings instructing victims to call certain phone numbers 
* remo.ps1, an IP address-gated launcher for "jujuzkt2.ps1," a browser redirector that matches window titles against a list, and if a configured URL is present, places a phishing URL on the clipboard, makes the browser, and sends a series of keypress events (Ctrl+L, Ctrl+V, and Enter) to take the victim to the phishing landing page 
One such redirect destination, "'bancaporinternetbbmx[.]online," contains a page-load Telegram notification script that harvests browser, device, and IP address details, and sends the information to a Telegram chat, alerting the operator that a redirected victim has reached the lure for follow-on attacks. 
"The scripts show strong signs of AI assistance, most likely by prompting a large language model in Spanish and then applying manual obfuscation afterward," Elastic said. 
"The code has a split personality, with clean, descriptive function names and heavy explanatory comments sitting next to hand-shortened variables and leftover generation artifacts. 
The placement of instruction-like comments directly above the code they describe suggests the authors have prompted an inline coding assistant such as Copilot or Cursor." 
Taken together, the findings represent the work of a threat actor who has leaned on AI to assemble a crude toolset that's best characterized by copy-paste batch files, shoddy craftsmanship, and operational security lapses. 
"Victims are kept as a passive feed while the operator watches a live dashboard and engages only the targets worth the effort, switching on browser redirects, vishing lockdowns, clipboard swaps, or a full RAT by IP, on demand," the researchers concluded. 
"Crude as it is, SCMBANKER already has real victims. 
The live victim counter and the labeled, tagged machines on the operator's own panels show that individual people are being actively targeted." 
Article reasoning-pattern comparisonThis article: 0.0%Ravie Lakshmanan: 1.5%The Hacker News: 2.0%Confirmation Bias0.0%This article: 2.7%Ravie Lakshmanan: 1.4%The Hacker News: 1.2%Anchoring Bias2.7%This article: 2.5%Ravie Lakshmanan: 2.2%The Hacker News: 3.3%Availability Heuristic2.5%This article: 6.0%Ravie Lakshmanan: 1.6%The Hacker News: 1.4%Representativeness Heuristic6.0%This article: 0.0%Ravie Lakshmanan: 1.0%The Hacker News: 0.6%Hindsight Bias0.0%This article: 20.2%Ravie Lakshmanan: 2.2%The Hacker News: 2.5%Overconfidence Bias20.2%This article: 1.1%Ravie Lakshmanan: 2.6%The Hacker News: 2.9%Framing Effect1.1%This article: 0.0%Ravie Lakshmanan: 0.9%The Hacker News: 1.1%Loss Aversion0.0%This article: 0.0%Ravie Lakshmanan: 0.4%The Hacker News: 0.6%Status Quo Bias0.0%This article: 0.0%Ravie Lakshmanan: 0.0%The Hacker News: 0.1%Sunk Cost Effect0.0%This article: 0.0%Ravie Lakshmanan: 1.2%The Hacker News: 1.3%Optimism Bias0.0%This article: 0.0%Ravie Lakshmanan: 1.3%The Hacker News: 1.6%Pessimism Bias0.0%This article: 15.6%Ravie Lakshmanan: 8.0%The Hacker News: 6.8%Negativity Bias15.6%This article: 0.0%Ravie Lakshmanan: 0.3%The Hacker News: 0.8%Self-Serving Bias0.0%This article: 4.4%Ravie Lakshmanan: 0.5%The Hacker News: 0.4%Fundamental Attribution Error4.4%This article: 0.0%Ravie Lakshmanan: 0.1%The Hacker News: 0.1%Actor-Observer Bias0.0%This article: 0.0%Ravie Lakshmanan: 0.1%The Hacker News: 0.1%In-Group Bias0.0%This article: 0.0%Ravie Lakshmanan: 1.4%The Hacker News: 0.4%Out-Group Homogeneity Bias0.0%This article: 0.0%Ravie Lakshmanan: 0.4%The Hacker News: 0.6%Halo Effect0.0%This article: 0.0%Ravie Lakshmanan: 0.0%The Hacker News: 0.0%Horn Effect0.0%This article: 0.0%Ravie Lakshmanan: 0.1%The Hacker News: 0.0%Dunning-Kruger Effect0.0%This article: 2.0%Ravie Lakshmanan: 2.2%The Hacker News: 1.4%Recency Bias2.0%This article: 0.0%Ravie Lakshmanan: 0.3%The Hacker News: 0.2%Primacy Effect0.0%This article: 0.0%Ravie Lakshmanan: 0.1%The Hacker News: 0.1%Blind-Spot Bias0.0%This article: 0.0%Ravie Lakshmanan: 0.2%The Hacker News: 0.1%Ad Hominem0.0%This article: 0.0%Ravie Lakshmanan: 0.0%The Hacker News: 0.1%Straw Man0.0%This article: 8.1%Ravie Lakshmanan: 4.8%The Hacker News: 4.0%Appeal to Authority8.1%This article: 0.0%Ravie Lakshmanan: 0.4%The Hacker News: 1.6%False Dilemma0.0%This article: 0.0%Ravie Lakshmanan: 0.3%The Hacker News: 0.5%Slippery Slope0.0%This article: 0.0%Ravie Lakshmanan: 0.0%The Hacker News: 0.1%Circular Reasoning0.0%This article: 6.5%Ravie Lakshmanan: 3.8%The Hacker News: 4.3%Hasty Generalization6.5%This article: 0.0%Ravie Lakshmanan: 0.2%The Hacker News: 0.1%Red Herring0.0%This article: 2.4%Ravie Lakshmanan: 0.2%The Hacker News: 0.2%Bandwagon2.4%This article: 8.4%Ravie Lakshmanan: 1.2%The Hacker News: 1.1%Appeal to Emotion8.4%This article: 0.0%Ravie Lakshmanan: 0.2%The Hacker News: 0.5%Begging the Question0.0%This article: 12.4%Ravie Lakshmanan: 2.1%The Hacker News: 1.9%Post Hoc (False Cause)12.4%This article: 0.0%Ravie Lakshmanan: 0.0%The Hacker News: 0.0%Tu Quoque0.0%This article: 0.0%Ravie Lakshmanan: 1.0%The Hacker News: 0.6%Burden of Proof0.0%This article: 0.0%Ravie Lakshmanan: 0.1%The Hacker News: 0.1%Appeal to Nature0.0%This article: 0.0%Ravie Lakshmanan: 0.0%The Hacker News: 0.3%Composition/Division0.0%This article: 5.4%Ravie Lakshmanan: 0.3%The Hacker News: 1.0%Anecdotal5.4%This article: 0.0%Ravie Lakshmanan: 0.1%The Hacker News: 0.1%No True Scotsman0.0%This article: 10.5%Ravie Lakshmanan: 4.0%The Hacker News: 2.3%Ambiguity (Equivocation)10.5%This article: 0.0%Ravie Lakshmanan: 0.0%The Hacker News: 0.0%Gambler’s Fallacy0.0%This article: 0.0%Ravie Lakshmanan: 0.0%The Hacker News: 0.0%Middle Ground0.0%This article: 0.0%Ravie Lakshmanan: 0.0%The Hacker News: 0.0%Personal Incredulity0.0%This article: 0.0%Ravie Lakshmanan: 0.0%The Hacker News: 0.1%Special Pleading0.0%This article: 0.0%Ravie Lakshmanan: 0.0%The Hacker News: 0.1%Genetic Fallacy0.0%This article: 24.5%Ravie Lakshmanan: 3.4%The Hacker News: 1.4%Unattributed Quote24.5%This article: 9.4%Ravie Lakshmanan: 2.8%The Hacker News: 1.0%Quote-first Misdirection9.4%This article: 1.1%Ravie Lakshmanan: 2.4%The Hacker News: 2.4%Biased Writer Voice1.1%This article: 0.0%Ravie Lakshmanan: 2.5%The Hacker News: 4.4%Indoctrination0.0%This article: 0.0%Ravie Lakshmanan: 0.0%The Hacker News: 0.0%Politically Left Leaning Bias0.0%This article: 0.0%Ravie Lakshmanan: 0.0%The Hacker News: 0.0%Politically Right Leaning Bias0.0%This article: 0.0%Ravie Lakshmanan: 0.5%The Hacker News: 3.0%Attempt to Sell a Product or S…0.0%

930 words analyzed.

Speakers

3speakers20%attributed speech742writer words
Voice mapSelect a segment to jump to its words
Writer's voice • 10 words • 100.0% coverageWriter's voice • 20 words • 0.0% coverageElastic Security Labs • 35 words • 100.0% coverageWriter's voice • 10 words • 0.0% coverageJia Yu Chan and Salim Bitam • 48 words • 100.0% coverageWriter's voice • 12 words • 100.0% coverageWriter's voice • 30 words • 0.0% coverageWriter's voice • 23 words • 0.0% coverageElastic • 35 words • 100.0% coverageWriter's voice • 1 words • 0.0% coverageWriter's voice • 32 words • 0.0% coverageWriter's voice • 22 words • 0.0% coverageWriter's voice • 27 words • 0.0% coverageElastic • 27 words • 0.0% coverageWriter's voice • 10 words • 100.0% coverageWriter's voice • 37 words • 0.0% coverageWriter's voice • 11 words • 0.0% coverageWriter's voice • 35 words • 0.0% coverageWriter's voice • 49 words • 0.0% coverageElastic • 17 words • 0.0% coverageWriter's voice • 14 words • 100.0% coverageWriter's voice • 18 words • 0.0% coverageWriter's voice • 16 words • 0.0% coverageWriter's voice • 5 words • 0.0% coverageWriter's voice • 9 words • 0.0% coverageWriter's voice • 17 words • 0.0% coverageWriter's voice • 16 words • 0.0% coverageWriter's voice • 6 words • 0.0% coverageWriter's voice • 38 words • 0.0% coverageWriter's voice • 23 words • 0.0% coverageWriter's voice • 55 words • 0.0% coverageWriter's voice • 41 words • 0.0% coverageElastic • 26 words • 0.0% coverageWriter's voice • 24 words • 100.0% coverageWriter's voice • 25 words • 0.0% coverageWriter's voice • 34 words • 0.0% coverageWriter's voice • 41 words • 100.0% coverageWriter's voice • 9 words • 100.0% coverageWriter's voice • 22 words • 0.0% coverage
100%flagged-word coverage
48 attributed words26% of attributed speech71% writer coverage
0%50.0%100.0%Unattributed Quote+85.2 ptsWriter: 14.8%Jia Yu Chan and Salim Bitam: 100.0%100.0%Quote-first Misdirection-11.7 ptsWriter: 11.7%Jia Yu Chan and Salim Bitam: 0.0%0.0%Biased Writer Voice-1.3 ptsWriter: 1.3%Jia Yu Chan and Salim Bitam: 0.0%0.0%

Attribution is sentence-level. Pattern percentages are calculated only from words assigned to that voice.

Loading…
Loading…
Loading…
Loading…

Analysis

Hover over highlighted words in the article to view the associated bias or fallacy analysis.