Actor Profile

REF6045 is a financially motivated threat actor conducting banking fraud operations against Mexican financial institutions and their customers. The actor targets banking, fintech, and cryptocurrency exchange users in Mexico, leveraging social engineering tactics to deploy the SCMBANKER malware toolkit. The group's motivation is financial gain through credential theft and unauthorized access to victim banking and cryptocurrency accounts. REF6045 demonstrates familiarity with the Mexican financial ecosystem and employs ClickFix social engineering techniques to achieve initial compromise.

TTPs (Tactics, Techniques, Procedures)

REF6045 employs ClickFix social engineering lures presenting fake CAPTCHA verification pages to deceive victims into manually executing malicious PowerShell commands (likely T1059.001 - PowerShell). This technique achieves initial access by exploiting user trust in legitimate verification mechanisms. The attack chain delivers SCMBANKER, a PowerShell-based malware toolkit designed for banking fraud operations. The use of fake CAPTCHA pages represents a user execution technique (T1204.001 - Malicious Link) combined with command and scripting interpreter abuse. The PowerShell-based nature of SCMBANKER suggests capabilities for credential access, collection, and potential exfiltration targeting financial data.

Targets & Patterns

REF6045 specifically targets Mexican banking customers, fintech platform users, and cryptocurrency exchange users. The geographic focus on Mexico suggests the actor possesses region-specific knowledge of financial institutions, user behaviors, and potentially Spanish-language social engineering content. The targeting of banking, fintech, and cryptocurrency sectors indicates the actor seeks high-value financial credentials and access to accounts with liquid assets. The use of ClickFix lures suggests victims are likely approached through phishing emails, malicious advertisements, or compromised websites that redirect to fake verification pages. This targeting pattern is consistent with financially motivated cybercrime operations focused on direct monetary theft rather than espionage or disruption.

Historical Context

The provided data does not include information about REF6045's previous campaigns or historical activity. ClickFix techniques have been increasingly observed across multiple threat actors since 2023-2024, representing an evolution in social engineering tactics that bypass traditional email security by requiring manual user interaction. The SCMBANKER toolkit appears to be purpose-built for this campaign, though connections to previous malware families or toolkits are not documented in the available intelligence. Further research would be needed to establish whether REF6045 represents a new actor or is a tracking designation for known cybercrime operations in the Latin American region.

Defensive Recommendations

  • Implement user awareness training specifically addressing fake CAPTCHA and ClickFix social engineering techniques, emphasizing that legitimate services never require users to paste commands into PowerShell or terminal windows
  • Deploy PowerShell logging (enable Script Block Logging and Transcription) and monitor for suspicious PowerShell execution, particularly commands launched from user-initiated processes or containing obfuscated code (Sysmon Event ID 4104, Windows Event ID 4103/4104)
  • Enforce PowerShell Constrained Language Mode and application control policies (AppLocker, WDAC) to restrict unauthorized script execution in user contexts, particularly for banking and financial sector employees
  • Monitor network traffic for connections to suspicious domains mimicking banking or CAPTCHA services, and implement DNS filtering to block known ClickFix infrastructure
  • Deploy endpoint detection rules for SCMBANKER indicators, including PowerShell-based credential access attempts, clipboard monitoring, browser data collection, and unusual process injection from PowerShell into banking applications

---

# Geopolitical Context

Geopolitical Context

The REF6045 campaign represents a financially motivated threat targeting Mexico's expanding digital financial ecosystem, which has experienced rapid growth in fintech adoption and cryptocurrency usage over the past five years. Mexico's position as Latin America's second-largest economy and its increasing digital payment infrastructure make it an attractive target for cybercriminal actors seeking financial gain. The use of ClickFix social engineering techniques—previously observed in various cybercrime operations globally—indicates the professionalization of threat actors operating in or targeting the Latin American region. This activity appears consistent with broader trends of cybercriminal groups exploiting social engineering rather than sophisticated technical exploits to compromise users in emerging digital markets.

State Actor Alignment

No state actor attribution is indicated in the available data. The campaign appears to be financially motivated cybercrime rather than state-sponsored activity. The targeting of banking, fintech, and cryptocurrency sectors is consistent with profit-driven criminal operations. Mexican authorities and financial regulators may coordinate with private sector partners to mitigate this threat, though no specific law enforcement or regulatory response has been reported. The activity does not appear to align with known state-sponsored cyber operations or geopolitical objectives beyond financial theft.

Business Impacty pro region

The campaign highlights vulnerabilities in Latin America's rapidly digitizing financial sector, where user awareness of sophisticated social engineering may lag behind adoption rates. For Mexico specifically, this threatens consumer confidence in digital banking and fintech services that the government has promoted as part of financial inclusion initiatives. Regional implications extend beyond Mexico, as similar ClickFix and fake CAPTCHA techniques could be adapted to target other Spanish-speaking markets in Central and South America where fintech growth is accelerating. The incident may prompt increased coordination among Latin American financial regulators and CERT organizations. For global financial institutions with operations in Mexico, the campaign underscores the need for enhanced customer security awareness programs tailored to local threat landscapes.

Forecast

If the REF6045 campaign proves successful in Mexico, it is likely that similar ClickFix-based financial fraud operations will proliferate across other Latin American markets with growing digital finance sectors, particularly in Spanish-speaking countries. Should Mexican financial regulators implement coordinated defensive measures and public awareness campaigns, the effectiveness of this specific technique may diminish domestically within weeks to months, though threat actors will likely adapt their social engineering lures. If cryptocurrency exchange targeting continues, international platforms operating in Mexico may enhance verification and authentication requirements, potentially impacting user experience. The SCMBANKER toolkit may be adopted or modified by other cybercriminal groups if it demonstrates operational success, leading to broader geographic distribution of this threat vector over the coming months.