Skip to main content

Balonx Sistema: The Face Behind the PhaaS Affecting Mexican Banking

0
Medium
Published: 08/19/2026 (08/19/2026, 15:40:17 UTC)
Source: AlienVault OTX General

Description

A sophisticated Phishing-as-a-Service platform called Balonx Sistema, operated from Mexico, targets over 20 financial institutions through tiered subscriptions. The platform employs real-time WebSocket session hijacking to defeat multi-factor authentication, distributing a Spyroid-based Android RAT via fake security alerts. Since October 2025, over 1,100 victims' credentials have been harvested. The operation includes CallFlow, an AI-driven vishing module using GPT-4o-mini, ElevenLabs synthetic voice, and OpenAI Whisper for automated telephone fraud, eliminating human operators. The platform uses continuous domain rotation across 350+ domains since 2019, maintains centralized PostgreSQL infrastructure, and is openly promoted through Facebook groups. The operator, identified as 'balonx', manages a sophisticated criminal enterprise generating approximately $99,000 USD through subscription-based access priced between 3,000-6,000 MXN weekly.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/26/2026, 01:48:45 UTC

Technical Analysis

Balonx Sistema is a sophisticated criminal Phishing-as-a-Service platform operated from Mexico, targeting financial institutions via tiered subscription access. It defeats multi-factor authentication by hijacking WebSocket sessions in real time and distributes a Spyroid Android RAT through deceptive security alerts. Since late 2025, it has compromised credentials from over 1,100 victims. The platform's CallFlow module automates voice phishing using AI technologies including GPT-4o-mini, ElevenLabs synthetic voice, and OpenAI Whisper, removing human involvement. It continuously rotates through more than 350 domains to evade detection and uses centralized PostgreSQL infrastructure. The operation is openly promoted on social media and generates significant revenue from criminals subscribing to the service.

Potential Impact

The platform compromises credentials of over 1,100 victims, primarily targeting Mexican financial institutions. It bypasses multi-factor authentication protections via WebSocket hijacking and installs a Spyroid Android RAT, enabling persistent access to victims' devices. The AI-driven vishing module automates telephone fraud, increasing the scale and efficiency of attacks without human involvement. Continuous domain rotation and centralized infrastructure enhance the platform's resilience and evasion capabilities. Financial losses are generated through subscription fees paid by criminals using the service, facilitating ongoing fraud campaigns.

Defensive Guidance

No official patch or fix is applicable as this is a criminal phishing platform rather than a software vulnerability. Defenders should focus on detecting and blocking the identified infrastructure indicators such as IP 196.251.84.11 and associated domains (e.g., soporte-aclaracion.xyz, balonx.online, callbalonx.info, panelbalonxfs.xyz, phishing-domain.xyz). Financial institutions should enhance monitoring for WebSocket hijacking attempts and suspicious Android app installations resembling the Spyroid RAT. User awareness campaigns about phishing and AI-generated fraudulent calls may reduce victimization. Collaboration with law enforcement and threat intelligence sharing is recommended to disrupt the platform's operations.

Affected Countries

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Author
AlienVault
Tlp
white
References
["https://www.group-ib.com/blog/balonx-sistema-mexico-phaas"]
Adversary
Balonx Sistema
Pulse Id
6a85ce6194c0be6ceb256c93

Indicators of Compromise

Ip

ValueDescriptionCopy
ip196.251.84.11
—

Domain

ValueDescriptionCopy
domainsoporte-aclaracion.xyz
—
domainbalonx.online
—
domaincallbalonx.info
—
domainpanelbalonxfs.xyz
—
domainphishing-domain.xyz
—

Url

ValueDescriptionCopy
urlhttp://panelbalonxfs.xyz/admin/api/api/gql
—
urlhttp://panelbalonxfs.xyz/admin/api/api/rest
—
urlhttp://panelbalonxfs.xyz/admin/api/api/token
—

Threat ID: 6a86b942acd9273b4955b7ec

Added to database: 08/20/2026, 08:22:26 UTC

Last enriched: 09/26/2026, 01:48:45 UTC

Last updated: 10/04/2026, 06:26:18 UTC

Views: 348

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

External Links

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses