A new cyberattack campaign is targeting banking users in Mexico. The attackers focus on bank customers, payment services, digital finance platforms, and cryptocurrency users. They use fake verification pages to trick people into installing malware. As a result, victims unknowingly give attackers access to their devices. The malware is known as SCMBANKER malware.
Fake Verification Pages Start the Attack
The attack begins with a fake security verification page. It looks similar to a common CAPTCHA test. Therefore, many users believe the page is safe. The page asks users to complete a simple image challenge. After that, it tells them to copy and run a command on their Windows computer.
Once the command runs, the malware installation begins. However, victims often do not notice anything suspicious. A fake Windows update screen appears to distract them. Meanwhile, the hidden script downloads several malicious files. As a result, the malware gains more control over the system.
Malware Gains Full Control
The malware checks whether it has administrator access. If it does not, it repeatedly asks the user to approve the request. Therefore, some users eventually click the approval button. After gaining permission, the malware locks mouse movement. It also keeps the fake update screen visible.
Next, the malware downloads additional tools. It also creates automatic startup settings. As a result, the malware launches every time the computer starts. Furthermore, it forces the system to restart so every malicious component becomes active.
SCMBANKER Malware Monitors Banking Activity
After installation, SCMBANKER malware watches for online banking activity. It checks open windows every second. If it detects a banking website, it begins collecting information. For example, it captures screenshots and records keyboard activity.
The malware also changes copied account numbers. Therefore, money transfers may go to criminal accounts instead. In addition, it redirects users to fake banking websites. It even displays fake security warnings that encourage victims to call fraudulent phone numbers.
Attackers Can Expand the Infection
The malware includes several separate modules. Each module performs a different task. For example, one module updates the malware automatically. Another module downloads remote access software. As a result, attackers can fully control the infected computer.
Some modules also execute additional commands. Others monitor financial websites or redirect web browsers. Furthermore, one module sends victim information to messaging services. This allows attackers to track successful infections in real time.
Researchers Found Signs of AI Assistance
Researchers discovered the campaign after finding an exposed server directory. The mistake revealed important files used in the operation. Therefore, investigators could study the complete malware toolkit. Their analysis uncovered many hidden features.
The code also showed signs of AI-assisted development. For example, many functions included detailed comments beside shortened variable names. However, manual changes also appeared throughout the code. Researchers believe attackers combined AI-generated code with their own edits.
The Campaign Continues to Threaten Users
The attack mainly targets Mexico’s financial sector. However, similar techniques could appear in other countries. Attackers carefully monitor victims before launching more aggressive actions. Therefore, they only focus on users with valuable banking activity.
The malware already has active victims. It allows attackers to redirect browsers, replace payment details, and install remote access tools. As a result, users may lose sensitive information or money. Security experts expect similar campaigns to continue evolving.
How to Prevent SCMBANKER Malware
Users should never run commands copied from unknown websites. They should also verify security prompts before granting administrator access. Furthermore, organizations should deploy endpoint protection that detects suspicious PowerShell activity and blocks malicious scripts before execution.
In addition, continuous security monitoring and managed threat detection services help identify unusual behavior early, reducing the risk of banking malware infections and limiting damage before attackers gain full control.
Sleep well, we got you covered.

