Balonx Sistema: Hackers Use AI Voice Calls and Fake Banking Pages to Bypass MFA and Steal Accounts

Balonx Sistema: Hackers Use AI Voice Calls and Fake Banking Pages to Bypass MFA and Steal Accounts

AI-Powered Phishing Campaign Targets Mexican Banking Customers in Real-Time Fraud Scheme

A sophisticated phishing-as-a-service (PhaaS) operation, tracked as Balonx Sistema, is combining AI-generated voice calls, live phishing pages, and Android malware to bypass multi-factor authentication (MFA) and hijack customer accounts at over 20 Mexican financial institutions. Since at least October 2025, the campaign has compromised credentials and financial data from more than 1,100 victims, leveraging a subscription-based model to enable large-scale fraud.

How the Attack Works

Balonx operates as a real-time phishing platform, using a persistent WebSocket connection to synchronize fraudulent pages with an attacker’s control panel. When a victim enters login details, the operator relays them to the legitimate bank site, triggering an MFA prompt then immediately displays a fake verification screen to capture the code. The platform supports 14 different screen types, allowing attackers to dynamically adapt the scam, requesting SMS codes, ATM PINs, card details, or cardless-withdrawal codes under the guise of a security check.

A separate CallFlow module enhances social engineering by using AI-driven voice synthesis to impersonate a bank representative (e.g., "Carolina"). The system automates outbound calls, making interactions feel personalized while steering victims toward phishing pages. In some cases, attackers push a malicious Android app disguised as a "bank-protection alert," which installs a Spyroid-based remote access trojan (RAT). Once deployed, the malware exfiltrates screen content, keystrokes, SMS messages, and banking app activity, enabling prolonged device control.

Infrastructure and Evasion Tactics

Balonx’s infrastructure, exposed via leaked GitHub repositories, reveals a rotating domain strategy to evade takedowns. Key indicators include:

  • Phishing domains: aclaraciones-digital[.]online, soporte-aclaracion[.]xyz
  • AI vishing portal: callbalonx[.]info
  • Android RAT C2 server: 196.251.84[.]11:7771/TCP
  • Malicious APK: Package name sacred.explosion, delivered via a fake "bank-protection" screen

The platform’s real-time relay technique exploits the gap between legitimate MFA prompts and fraudulent responses, making security checks appear authentic. Financial institutions are advised to monitor for unusual WebSocket activity, suspicious redirect chains, and high-risk MFA requests, while FIDO2 hardware keys offer stronger protection against such attacks.

Impact and Scope

Balonx lowers the barrier for cybercriminals by offering subscription-based access, including individual and office plans for multiple operators. Its automation and scalability make it a potent tool for large-scale banking fraud, with affiliates targeting customers through urgent calls, fake websites, and malicious apps. The campaign underscores the limitations of SMS-based MFA when attackers can intercept codes in real time. Victims are urged to verify unexpected calls independently and avoid installing apps from unverified sources.

Source: https://cybersecuritynews.com/hackers-use-ai-voice-calls/

Group-IB cybersecurity rating report: https://www.rankiteo.com/company/group-ib

"id": "GRO1787156738",
"linkid": "group-ib",
"type": "Cyber Attack",
"date": "10/2025",
"severity": "100",
"impact": "5",
"explanation": "Attack threatening the organization's existence"
{'affected_entities': [{'customers_affected': '1,100+',
                        'industry': 'Banking',
                        'location': 'Mexico',
                        'type': 'Financial Institutions'}],
 'attack_vector': ['AI-generated voice calls',
                   'Live phishing pages',
                   'Android malware',
                   'WebSocket-based real-time relay'],
 'customer_advisories': 'Victims urged to verify unexpected calls '
                        'independently and avoid installing apps from '
                        'unverified sources.',
 'data_breach': {'data_exfiltration': 'Yes (via Spyroid RAT)',
                 'number_of_records_exposed': '1,100+',
                 'personally_identifiable_information': 'Yes',
                 'sensitivity_of_data': 'High (financial and personal data)',
                 'type_of_data_compromised': ['Credentials',
                                              'Financial data',
                                              'MFA codes',
                                              'SMS messages',
                                              'Banking app activity',
                                              'Personally identifiable '
                                              'information (PII)']},
 'date_detected': '2025-10-01',
 'description': 'A sophisticated phishing-as-a-service (PhaaS) operation, '
                'tracked as Balonx Sistema, is combining AI-generated voice '
                'calls, live phishing pages, and Android malware to bypass '
                'multi-factor authentication (MFA) and hijack customer '
                'accounts at over 20 Mexican financial institutions. The '
                'campaign has compromised credentials and financial data from '
                'more than 1,100 victims since October 2025, leveraging a '
                'subscription-based model for large-scale fraud.',
 'impact': {'brand_reputation_impact': 'Erosion of customer trust in affected '
                                       'banks',
            'data_compromised': 'Credentials, financial data, MFA codes, SMS '
                                'messages, banking app activity, personally '
                                'identifiable information (PII)',
            'identity_theft_risk': 'High (PII and financial data exposed)',
            'operational_impact': 'Account hijacking, unauthorized '
                                  'transactions, prolonged device control via '
                                  'RAT',
            'payment_information_risk': 'High (card details, ATM PINs, '
                                        'cardless-withdrawal codes captured)',
            'systems_affected': ['Customer banking accounts',
                                 'Android devices']},
 'initial_access_broker': {'backdoors_established': 'Spyroid-based RAT on '
                                                    'Android devices',
                           'entry_point': ['Phishing pages',
                                           'AI-generated voice calls',
                                           'Malicious Android apps'],
                           'high_value_targets': 'Banking customers with '
                                                 'active accounts'},
 'lessons_learned': 'Limitations of SMS-based MFA highlighted; FIDO2 hardware '
                    'keys recommended for stronger protection. Need for '
                    'independent verification of unexpected calls and '
                    'avoidance of unverified app installations.',
 'motivation': 'Financial gain through large-scale banking fraud',
 'post_incident_analysis': {'corrective_actions': ['Adoption of FIDO2 hardware '
                                                   'keys',
                                                   'Enhanced monitoring for '
                                                   'WebSocket and MFA '
                                                   'anomalies',
                                                   'Customer education on '
                                                   'phishing and app security'],
                            'root_causes': ['Exploitation of SMS-based MFA '
                                            'gaps',
                                            'Real-time phishing relay via '
                                            'WebSocket',
                                            'Social engineering via AI voice '
                                            'synthesis',
                                            'Malicious Android app '
                                            'distribution']},
 'recommendations': ['Monitor for unusual WebSocket activity and suspicious '
                     'redirect chains',
                     'Implement FIDO2 hardware keys for MFA',
                     'Educate customers on verifying unexpected calls '
                     'independently',
                     'Avoid installing apps from unverified sources',
                     'Enhance monitoring for high-risk MFA requests'],
 'references': [{'source': 'GitHub repository leak (Balonx infrastructure)'},
                {'source': 'Phishing domains',
                 'url': 'http://aclaraciones-digital[.]online, '
                        'http://soporte-aclaracion[.]xyz'},
                {'source': 'AI vishing portal',
                 'url': 'http://callbalonx[.]info'},
                {'source': 'Android RAT C2 server',
                 'url': '196.251.84[.]11:7771/TCP'}],
 'response': {'enhanced_monitoring': 'Monitoring for unusual WebSocket '
                                     'activity, suspicious redirect chains, '
                                     'and high-risk MFA requests advised'},
 'threat_actor': 'Balonx Sistema (PhaaS operators and affiliates)',
 'title': 'AI-Powered Phishing Campaign Targets Mexican Banking Customers in '
          'Real-Time Fraud Scheme',
 'type': 'Phishing-as-a-Service (PhaaS)',
 'vulnerability_exploited': 'SMS-based MFA interception, lack of FIDO2 '
                            'hardware keys'}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.