Fake CAPTCHA Pages Are Stealing From Mexican Bank Customers

Elastic Security Labs is tracking a fraud campaign, dubbed REF6045, that tricks people into pasting a malicious command from a bogus 'prove you're human' page.

ThreatVectr NewsdeskAI-assistedPublished Updated · Editor: Lee Brown· 3 min read
Illustration: a laptop screen showing a generic blurred verification prompt with a checkbox, warm desk lamp light
Illustration made with AI. Not a photograph of the events described.
Share

Key points

  • Elastic Security Labs is tracking a fraud campaign, called REF6045, aimed at customers of Mexican banks, fintech apps, payment processors and crypto exchanges.
  • Victims are lured to fake CAPTCHA pages and told to run a command that quietly installs malware.
  • The malware is a PowerShell toolkit named SCMBANKER, built to steal banking credentials and drain accounts.
  • The technique is known as ClickFix: a social engineering trick where the victim does the hackers' work by pasting the command themselves.

There's a new banking scam running in Mexico, and it starts with something that looks completely ordinary: a CAPTCHA.

A website asks you to tick a box or copy a short code to prove you're not a robot. In this campaign, that check is a fake, and following its instructions hands your computer to criminals.

Elastic Security Labs, the research arm of the search company Elastic, is tracking the operation under the codename REF6045. First reported by The Hacker News, the campaign targets customers of Mexican banks, fintech services (financial apps that work like a bank on your phone), payment processors and cryptocurrency exchanges.

How does the scam actually work?

The hackers push victims to a fake verification page that pretends to be a normal anti-bot check. Instead of clicking a box, the page tells the visitor to open the Windows Run box and paste in a short command it has already copied to their clipboard.

That command is the trap. Once pasted, it installs a PowerShell toolkit that Elastic calls SCMBANKER. PowerShell is a scripting tool built into Windows, and it's a favourite of attackers because the operating system already trusts it.

The malware then focuses on what the criminals actually want: your money. It targets login details for Mexican banks and crypto exchanges, sitting quietly on the machine until the next time you sign in.

Why 'ClickFix' matters

Security researchers call this style of attack ClickFix. The idea is straightforward and, frankly, clever. Rather than exploiting a software bug, the hackers exploit the person at the keyboard.

You're told there's a small problem, a captcha to solve or a document that won't open, and helpfully given the 'fix' to paste in. Paste it, infect yourself. No fancy zero-day required.

We've been watching ClickFix mature fast. On 1 July we reported how researchers pulled roughly 3,000 live payloads from ClickFix infrastructure and found a polymorphic delivery pipeline built to defeat Windows script scanning. REF6045 is that same delivery logic, now pointed at a specific country and a specific financial sector.

It's the modern cousin of the old email attachment trick, dressed up for 2026.

Should ordinary customers be worried?

If you bank in Mexico, yes, pay attention, but don't panic. One rule defeats this entire class of attack.

No legitimate website will ever ask you to open a Run box or a Terminal window and paste in a command to prove you're human. Not your bank, not a video site. If a page demands that, close the tab.

Already ran the command? Disconnect from the internet, call your bank on the number printed on your card, and get the machine checked by someone you trust. Watch your accounts for small test transactions in the days after; criminals often try a tiny charge first to confirm the account is live before draining it.

The bigger picture

SCMBANKER isn't a technical marvel. It's a reminder that as browsers and operating systems get harder to crack, attackers spend more effort convincing you to open the door yourself. That's a training problem as much as a security one.

Expect more ClickFix campaigns, in more languages, aimed at more banks, well into next year.

© 2026 Threat Vectr