Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

Balonx Sistema: The Face Behind the PhaaS Affecting Mexican Banking

0
Medium
Published: 08/19/2026 (08/19/2026, 15:40:17 UTC)
Source: AlienVault OTX General

Description

A sophisticated Phishing-as-a-Service platform called Balonx Sistema, operated from Mexico, targets over 20 financial institutions through tiered subscriptions. The platform employs real-time WebSocket session hijacking to defeat multi-factor authentication, distributing a Spyroid-based Android RAT via fake security alerts. Since October 2025, over 1,100 victims' credentials have been harvested. The operation includes CallFlow, an AI-driven vishing module using GPT-4o-mini, ElevenLabs synthetic voice, and OpenAI Whisper for automated telephone fraud, eliminating human operators. The platform uses continuous domain rotation across 350+ domains since 2019, maintains centralized PostgreSQL infrastructure, and is openly promoted through Facebook groups. The operator, identified as 'balonx', manages a sophisticated criminal enterprise generating approximately $99,000 USD through subscription-based access priced between 3,000-6,000 MXN weekly.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/20/2026, 08:42:44 UTC

Technical Analysis

Balonx Sistema is a criminal Phishing-as-a-Service platform originating from Mexico that targets financial institutions through tiered subscription models. It leverages real-time WebSocket session hijacking to circumvent multi-factor authentication protections and distributes a Spyroid-based Android Remote Access Trojan (RAT) via deceptive security alerts. The operation has compromised credentials of more than 1,100 victims since late 2025. Additionally, it features CallFlow, an AI-powered vishing system utilizing GPT-4o-mini, ElevenLabs synthetic voice technology, and OpenAI Whisper for automated voice fraud, eliminating the need for human operators. The platform maintains a centralized PostgreSQL backend and rotates through more than 350 domains continuously since 2019 to evade detection. It is openly advertised in Facebook groups and generates significant illicit revenue through subscription fees ranging from 3,000 to 6,000 MXN weekly.

Potential Impact

The threat compromises user credentials from over 1,100 victims, primarily targeting Mexican financial institutions. It defeats multi-factor authentication via WebSocket hijacking and delivers a Spyroid Android RAT, enabling attackers to gain persistent access to victims' devices. The AI-driven vishing module automates telephone fraud, increasing the scale and efficiency of attacks without human involvement. The platform's domain rotation and centralized infrastructure enhance its resilience and evasion capabilities. Financial losses are generated through subscription fees paid by criminals using the service, facilitating ongoing fraud campaigns.

Defensive Guidance

No official patch or fix is applicable as this is a criminal phishing platform rather than a software vulnerability. Defenders should focus on detecting and blocking the identified infrastructure indicators such as IP 196.251.84.11 and associated domains (e.g., soporte-aclaracion.xyz, balonx.online, callbalonx.info, panelbalonxfs.xyz, phishing-domain.xyz). Financial institutions should enhance monitoring for WebSocket hijacking attempts and suspicious Android app installations resembling Spyroid RAT. Awareness campaigns to educate users about phishing and fraudulent calls leveraging AI-generated voices may reduce victimization. Collaboration with law enforcement and threat intelligence sharing is recommended to disrupt the platform's operations.

Affected Countries

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Author
AlienVault
Tlp
white
References
["https://www.group-ib.com/blog/balonx-sistema-mexico-phaas"]
Adversary
Balonx Sistema
Pulse Id
6a85ce6194c0be6ceb256c93
Threat Score
null

Indicators of Compromise

Ip

ValueDescriptionCopy
ip196.251.84.11

Domain

ValueDescriptionCopy
domainsoporte-aclaracion.xyz
domainbalonx.online
domaincallbalonx.info
domainpanelbalonxfs.xyz
domainphishing-domain.xyz

Url

ValueDescriptionCopy
urlhttp://panelbalonxfs.xyz/admin/api/api/gql
urlhttp://panelbalonxfs.xyz/admin/api/api/rest
urlhttp://panelbalonxfs.xyz/admin/api/api/token

Threat ID: 6a86b942acd9273b4955b7ec

Added to database: 08/20/2026, 08:22:26 UTC

Last enriched: 08/20/2026, 08:42:44 UTC

Last updated: 08/20/2026, 12:06:09 UTC

Views: 7

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

External Links

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses