Cybersecurity in the Mexican financial sector faces a growing threat with the emergence of campaigns that combine social engineering and remote execution techniques. A group of activity, internally known as REF6045, has recently been identified using ClickFix lures to infect users of banks, fintechs, payment processors, and cryptocurrency exchanges. The attack begins with a fake CAPTCHA verification page that, upon interaction, tricks the victim into copying and executing a malicious command on their system. This command deploys a set of PowerShell tools dubbed SCMBANKER, designed to steal credentials, manipulate transactions, and persist in the infected environment. The effectiveness of the deception lies in its legitimate appearance and the trust users place in visual security mechanisms.
For companies operating in the digital financial ecosystem, this type of campaign underscores the need to adopt a comprehensive protection approach that goes beyond traditional antivirus. Prevention requires combining continuous staff training, updating response protocols, and, above all, robust technological solutions. In this context, having a partner that offers custom software with secure architectures, capable of including artificial intelligence for businesses and early detection mechanisms, becomes strategic. Additionally, integrating AWS and Azure cloud services enables the deployment of scalable and monitored environments, while cybersecurity solutions like pentesting and audits help identify vulnerabilities before they are exploited.
This incident also highlights the importance of business intelligence applied to security. Using tools like Power BI and AI agents, it is possible to correlate access events, anomalous behavior, and lateral movement patterns on the network, generating early alerts that minimize impact. At Q2BSTUDIO, we offer an ecosystem of process automation that, together with custom application development, allows financial organizations to shield their operations without sacrificing user experience. The SCMBANKER threat reminds us that innovation in attacks demands equally agile innovation in defenses, and that collaboration between technology and security experts is the only way to stay ahead of these emerging risks.

.jpg)
