Balonx Sistema: The Face Behind the PhaaS Affecting Mexican Banking
Description
A sophisticated Phishing-as-a-Service platform called Balonx Sistema, operated from Mexico, targets over 20 financial institutions through tiered subscriptions. The platform employs real-time WebSocket session hijacking to defeat multi-factor authentication, distributing a Spyroid-based Android RAT via fake security alerts. Since October 2025, over 1,100 victims' credentials have been harvested. The operation includes CallFlow, an AI-driven vishing module using GPT-4o-mini, ElevenLabs synthetic voice, and OpenAI Whisper for automated telephone fraud, eliminating human operators. The platform uses continuous domain rotation across 350+ domains since 2019, maintains centralized PostgreSQL infrastructure, and is openly promoted through Facebook groups. The operator, identified as 'balonx', manages a sophisticated criminal enterprise generating approximately $99,000 USD through subscription-based access priced between 3,000-6,000 MXN weekly.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Balonx Sistema is a sophisticated criminal Phishing-as-a-Service platform operated from Mexico, targeting financial institutions via tiered subscription access. It defeats multi-factor authentication by hijacking WebSocket sessions in real time and distributes a Spyroid Android RAT through deceptive security alerts. Since late 2025, it has compromised credentials from over 1,100 victims. The platform's CallFlow module automates voice phishing using AI technologies including GPT-4o-mini, ElevenLabs synthetic voice, and OpenAI Whisper, removing human involvement. It continuously rotates through more than 350 domains to evade detection and uses centralized PostgreSQL infrastructure. The operation is openly promoted on social media and generates significant revenue from criminals subscribing to the service.
Potential Impact
The platform compromises credentials of over 1,100 victims, primarily targeting Mexican financial institutions. It bypasses multi-factor authentication protections via WebSocket hijacking and installs a Spyroid Android RAT, enabling persistent access to victims' devices. The AI-driven vishing module automates telephone fraud, increasing the scale and efficiency of attacks without human involvement. Continuous domain rotation and centralized infrastructure enhance the platform's resilience and evasion capabilities. Financial losses are generated through subscription fees paid by criminals using the service, facilitating ongoing fraud campaigns.
Defensive Guidance
No official patch or fix is applicable as this is a criminal phishing platform rather than a software vulnerability. Defenders should focus on detecting and blocking the identified infrastructure indicators such as IP 196.251.84.11 and associated domains (e.g., soporte-aclaracion.xyz, balonx.online, callbalonx.info, panelbalonxfs.xyz, phishing-domain.xyz). Financial institutions should enhance monitoring for WebSocket hijacking attempts and suspicious Android app installations resembling the Spyroid RAT. User awareness campaigns about phishing and AI-generated fraudulent calls may reduce victimization. Collaboration with law enforcement and threat intelligence sharing is recommended to disrupt the platform's operations.
Affected Countries
Technical Details
- Author
- AlienVault
- Tlp
- white
- References
- ["https://www.group-ib.com/blog/balonx-sistema-mexico-phaas"]
- Adversary
- Balonx Sistema
- Pulse Id
- 6a85ce6194c0be6ceb256c93
Indicators of Compromise
Ip
| Value | Description | Copy |
|---|---|---|
ip196.251.84.11 | — |
Domain
| Value | Description | Copy |
|---|---|---|
domainsoporte-aclaracion.xyz | — | |
domainbalonx.online | — | |
domaincallbalonx.info | — | |
domainpanelbalonxfs.xyz | — | |
domainphishing-domain.xyz | — |
Url
| Value | Description | Copy |
|---|---|---|
urlhttp://panelbalonxfs.xyz/admin/api/api/gql | — | |
urlhttp://panelbalonxfs.xyz/admin/api/api/rest | — | |
urlhttp://panelbalonxfs.xyz/admin/api/api/token | — |
Threat ID: 6a86b942acd9273b4955b7ec
Added to database: 08/20/2026, 08:22:26 UTC
Last enriched: 09/26/2026, 01:48:45 UTC
Last updated: 10/04/2026, 06:26:18 UTC
Views: 348
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.