Balonx Sistema: The Face Behind the PhaaS Affecting Mexican Banking
A sophisticated Phishing-as-a-Service platform called Balonx Sistema, operated from Mexico, targets over 20 financial institutions through tiered subscriptions. The platform employs real-time WebSocket session hijacking to defeat multi-factor authentication, distributing a Spyroid-based Android RAT via fake security alerts. Since October 2025, over 1,100 victims' credentials have been harvested. The operation includes CallFlow, an AI-driven vishing module using GPT-4o-mini, ElevenLabs synthetic voice, and OpenAI Whisper for automated telephone fraud, eliminating human operators. The platform uses continuous domain rotation across 350+ domains since 2019, maintains centralized PostgreSQL infrastructure, and is openly promoted through Facebook groups. The operator, identified as 'balonx', manages a sophisticated criminal enterprise generating approximately $99,000 USD through subscription-based access priced between 3,000-6,000 MXN weekly.
AI Analysis
Technical Summary
Balonx Sistema is a criminal Phishing-as-a-Service platform originating from Mexico that targets financial institutions through tiered subscription models. It leverages real-time WebSocket session hijacking to circumvent multi-factor authentication protections and distributes a Spyroid-based Android Remote Access Trojan (RAT) via deceptive security alerts. The operation has compromised credentials of more than 1,100 victims since late 2025. Additionally, it features CallFlow, an AI-powered vishing system utilizing GPT-4o-mini, ElevenLabs synthetic voice technology, and OpenAI Whisper for automated voice fraud, eliminating the need for human operators. The platform maintains a centralized PostgreSQL backend and rotates through more than 350 domains continuously since 2019 to evade detection. It is openly advertised in Facebook groups and generates significant illicit revenue through subscription fees ranging from 3,000 to 6,000 MXN weekly.
Potential Impact
The threat compromises user credentials from over 1,100 victims, primarily targeting Mexican financial institutions. It defeats multi-factor authentication via WebSocket hijacking and delivers a Spyroid Android RAT, enabling attackers to gain persistent access to victims' devices. The AI-driven vishing module automates telephone fraud, increasing the scale and efficiency of attacks without human involvement. The platform's domain rotation and centralized infrastructure enhance its resilience and evasion capabilities. Financial losses are generated through subscription fees paid by criminals using the service, facilitating ongoing fraud campaigns.
Mitigation Recommendations
No official patch or fix is applicable as this is a criminal phishing platform rather than a software vulnerability. Defenders should focus on detecting and blocking the identified infrastructure indicators such as IP 196.251.84.11 and associated domains (e.g., soporte-aclaracion.xyz, balonx.online, callbalonx.info, panelbalonxfs.xyz, phishing-domain.xyz). Financial institutions should enhance monitoring for WebSocket hijacking attempts and suspicious Android app installations resembling Spyroid RAT. Awareness campaigns to educate users about phishing and fraudulent calls leveraging AI-generated voices may reduce victimization. Collaboration with law enforcement and threat intelligence sharing is recommended to disrupt the platform's operations.
Affected Countries
Mexico
Indicators of Compromise
- ip: 196.251.84.11
- domain: soporte-aclaracion.xyz
- domain: balonx.online
- domain: callbalonx.info
- domain: panelbalonxfs.xyz
- url: http://panelbalonxfs.xyz/admin/api/api/gql
- url: http://panelbalonxfs.xyz/admin/api/api/rest
- url: http://panelbalonxfs.xyz/admin/api/api/token
- domain: phishing-domain.xyz
Balonx Sistema: The Face Behind the PhaaS Affecting Mexican Banking
Description
A sophisticated Phishing-as-a-Service platform called Balonx Sistema, operated from Mexico, targets over 20 financial institutions through tiered subscriptions. The platform employs real-time WebSocket session hijacking to defeat multi-factor authentication, distributing a Spyroid-based Android RAT via fake security alerts. Since October 2025, over 1,100 victims' credentials have been harvested. The operation includes CallFlow, an AI-driven vishing module using GPT-4o-mini, ElevenLabs synthetic voice, and OpenAI Whisper for automated telephone fraud, eliminating human operators. The platform uses continuous domain rotation across 350+ domains since 2019, maintains centralized PostgreSQL infrastructure, and is openly promoted through Facebook groups. The operator, identified as 'balonx', manages a sophisticated criminal enterprise generating approximately $99,000 USD through subscription-based access priced between 3,000-6,000 MXN weekly.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Balonx Sistema is a criminal Phishing-as-a-Service platform originating from Mexico that targets financial institutions through tiered subscription models. It leverages real-time WebSocket session hijacking to circumvent multi-factor authentication protections and distributes a Spyroid-based Android Remote Access Trojan (RAT) via deceptive security alerts. The operation has compromised credentials of more than 1,100 victims since late 2025. Additionally, it features CallFlow, an AI-powered vishing system utilizing GPT-4o-mini, ElevenLabs synthetic voice technology, and OpenAI Whisper for automated voice fraud, eliminating the need for human operators. The platform maintains a centralized PostgreSQL backend and rotates through more than 350 domains continuously since 2019 to evade detection. It is openly advertised in Facebook groups and generates significant illicit revenue through subscription fees ranging from 3,000 to 6,000 MXN weekly.
Potential Impact
The threat compromises user credentials from over 1,100 victims, primarily targeting Mexican financial institutions. It defeats multi-factor authentication via WebSocket hijacking and delivers a Spyroid Android RAT, enabling attackers to gain persistent access to victims' devices. The AI-driven vishing module automates telephone fraud, increasing the scale and efficiency of attacks without human involvement. The platform's domain rotation and centralized infrastructure enhance its resilience and evasion capabilities. Financial losses are generated through subscription fees paid by criminals using the service, facilitating ongoing fraud campaigns.
Defensive Guidance
No official patch or fix is applicable as this is a criminal phishing platform rather than a software vulnerability. Defenders should focus on detecting and blocking the identified infrastructure indicators such as IP 196.251.84.11 and associated domains (e.g., soporte-aclaracion.xyz, balonx.online, callbalonx.info, panelbalonxfs.xyz, phishing-domain.xyz). Financial institutions should enhance monitoring for WebSocket hijacking attempts and suspicious Android app installations resembling Spyroid RAT. Awareness campaigns to educate users about phishing and fraudulent calls leveraging AI-generated voices may reduce victimization. Collaboration with law enforcement and threat intelligence sharing is recommended to disrupt the platform's operations.
Affected Countries
Technical Details
- Author
- AlienVault
- Tlp
- white
- References
- ["https://www.group-ib.com/blog/balonx-sistema-mexico-phaas"]
- Adversary
- Balonx Sistema
- Pulse Id
- 6a85ce6194c0be6ceb256c93
- Threat Score
- null
Indicators of Compromise
Ip
| Value | Description | Copy |
|---|---|---|
ip196.251.84.11 | — |
Domain
| Value | Description | Copy |
|---|---|---|
domainsoporte-aclaracion.xyz | — | |
domainbalonx.online | — | |
domaincallbalonx.info | — | |
domainpanelbalonxfs.xyz | — | |
domainphishing-domain.xyz | — |
Url
| Value | Description | Copy |
|---|---|---|
urlhttp://panelbalonxfs.xyz/admin/api/api/gql | — | |
urlhttp://panelbalonxfs.xyz/admin/api/api/rest | — | |
urlhttp://panelbalonxfs.xyz/admin/api/api/token | — |
Threat ID: 6a86b942acd9273b4955b7ec
Added to database: 08/20/2026, 08:22:26 UTC
Last enriched: 08/20/2026, 08:42:44 UTC
Last updated: 08/20/2026, 12:06:09 UTC
Views: 7
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.