Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Leaked Stripe Merchant API Keys Expose Payment and Payout Capabilities
August 19, 2026
AI Voice Phishing Bypasses MFA, Steals Accounts with Fake Banking Pages
August 19, 2026
China Hackers Use Malicious VHD Disguised as JPEG to Deploy QUICAgent Backdoor
August 19, 2026
Home/CyberSecurity News/AI Voice Phishing Bypasses MFA, Steals Accounts with Fake Banking Pages
CyberSecurity News

AI Voice Phishing Bypasses MFA, Steals Accounts with Fake Banking Pages

Key Takeaways A sophisticated phishing-as-a-service (PhaaS) operation, “Balonx Sistema,” is actively targeting Mexican financial institutions. The campaign employs AI-generated voice...

David kimber
David kimber
August 19, 2026 5 Min Read
2 0

Key Takeaways

  • A sophisticated phishing-as-a-service (PhaaS) operation, “Balonx Sistema,” is actively targeting Mexican financial institutions.
  • The campaign employs AI-generated voice calls and real-time fake banking pages to bypass multi-factor authentication (MFA).
  • It has already compromised over 1,100 individuals, stealing credentials and financial data.
  • Balonx Sistema leverages a multi-stage attack that can escalate from account phishing to full device takeover via an Android remote access trojan (RAT).

AI Voice Phishing Bypasses MFA, Steals Accounts with Fake Banking Pages

Cybercriminals are deploying an advanced phishing-as-a-service (PhaaS) platform that combines AI-powered voice calls with meticulously crafted fake banking websites to compromise user accounts, even circumventing multi-factor authentication (MFA) protocols. This sophisticated operation, identified as Balonx Sistema, provides attackers with a dynamic, real-time view of a victim’s interaction with the phishing site, enabling them to solicit sensitive information precisely when required.

Table Of Content

  • Key Takeaways
  • AI Voice Phishing Bypasses MFA, Steals Accounts with Fake Banking Pages
  • Sophisticated Phishing with Real-time Interaction
  • Mobile Access Extends the Fraud
  • What You Should Do
  • Indicators of Compromise (IoCs):-

The Balonx Sistema campaign has set its sights on over 20 financial institutions in Mexico, successfully exfiltrating credentials and other financial data from more than 1,100 victims since at least October 2023. The platform operates as a subscription service, significantly lowering the entry barrier for threat actors seeking to launch large-scale banking scams. It offers various subscription tiers, including individual and “office” plans, which grant multiple operators controlled access to active victim sessions and a selection of targeted banking brands.

Security researchers at Group-IB uncovered the platform after analyzing leaked GitHub repositories that exposed critical components of its infrastructure and affiliate network. According to Group-IB said in a report, Balonx Sistema integrates live phishing, an Android remote access tool, and automated voice fraud. This combination creates a blended attack that transitions seamlessly from an urgent phone call to a convincing fraudulent website, and in some instances, culminates in the installation of a malicious mobile application. This complex methodology highlights the inadequacy of SMS-based MFA alone against determined attackers who actively guide victims through the compromise process.

Sophisticated Phishing with Real-time Interaction

Balonx Sistema utilizes a persistent WebSocket connection to maintain a real-time link between the phishing page displayed to the victim and the criminal’s command-and-control panel. This allows for dynamic interaction. Once a target inputs their banking credentials, the operator can immediately relay these details to the legitimate bank’s website, triggering an MFA prompt. Simultaneously, a corresponding fake verification screen is presented to the victim on the phishing site.

The precise timing of these prompts is crucial to the scam’s effectiveness. Victims may be asked for various verification details, including SMS codes, purchase approval codes, ATM PINs, full card details, or cardless withdrawal codes, all under the guise of a routine bank security check. Balonx Sistema is equipped with 14 distinct screen types, enabling affiliates to adapt the narrative as the session progresses and compel the victim to complete all requested steps. This technique mirrors advanced phishing attacks that bypass MFA by positioning the attacker as an intermediary between the user and the legitimate service, rather than merely collecting static credentials. This “man-in-the-middle” approach makes the fraudulent page appear authentic because it responds dynamically while the genuine bank session is active.

A dedicated “CallFlow” module further enhances the social engineering aspect of the attack. This module incorporates a language model, speech-to-text processing, and synthetic speech to conduct automated calls, impersonating a fabricated bank representative named “Carolina.” This automation allows the platform to execute outbound campaigns without requiring a human operator for every conversation, making suspicious calls feel personalized and responsive. This danger is also evident in recent reports of automated bank support calls, where callers can direct targets to fake pages, then exploit these interactions to obtain credentials or persuade them to install malicious software.

Mobile Access Extends the Fraud

Beyond credential theft, Balonx Sistema also propagates a Spyroid-based Android remote access trojan (RAT). This malware is distributed via a deceptive screen that masquerades as a bank-protection alert. Upon successful installation, the malicious app establishes a persistent connection with its command-and-control server, enabling criminals to exfiltrate screen content, keystrokes, SMS messages, and activity from legitimate banking applications. The RAT’s persistent connection is designed to prevent timeouts, granting the operator uninterrupted access to the compromised device long after the initial deception.

This second stage elevates an account-phishing attempt into a potential device takeover. This aligns with a broader trend in Android remote-control banking threats, where attackers use fraudulent websites or calls to trick users into installing malicious applications outside official app stores, thereby gaining deeper access to the victim’s smartphone.

What You Should Do

  • Verify Calls Independently: If you receive an unexpected call from your bank, terminate the call and independently contact your bank using the official phone number listed on your bank card or within the official banking app. Do not use any numbers provided by the caller.
  • Never Install Unsolicited Apps: Refrain from installing any applications suggested by an unverified caller or website. Always download banking apps directly from official app stores (Google Play Store, Apple App Store).
  • Guard Sensitive Information: Be highly suspicious of any requests for your ATM PIN, CVV, or to scan your bank card over the phone or on an unfamiliar website. Legitimate banks will rarely ask for this information in such a manner.
  • Monitor for Suspicious Activity: Financial institutions should actively monitor their infrastructure for indicators of compromise (IoCs) related to Balonx Sistema, including unusual WebSocket activity and suspicious redirect chains.
  • Enhance MFA for High-Value Users: For critical accounts and high-value users, implement hardware security keys based on FIDO2 standards. These are significantly more resilient to real-time relay attacks than SMS-based one-time passwords.
  • Report and Act Immediately: If you suspect you have shared information with a fraudulent entity, immediately contact your bank through verified official channels, reset all relevant credentials, and thoroughly review your recent transaction history for any unauthorized activity.

Indicators of Compromise (IoCs):-

Type Indicator Description
Domain Aclaraciones-digital[.]online Balonx campaign infrastructure
Domain soporte-aclaracion[.]xyz Balonx campaign infrastructure
Domain balonx[.]online Balonx campaign infrastructure
Domain callbalonx[.]info CallFlow AI vishing login portal
Domain panelbalonxfs[.]xyz CallFlow FreePBX backend and UCP
IP Address 196.251.84[.]11 Android RAT command-and-control server
Network Port 7771/TCP Android RAT command-and-control port
IP Address 85.31.235[.]109 CallFlow SIP server
Network Port 5160/TCP CallFlow SIP service port
API Endpoint panelbalonxfs[.]xyz/admin/api/api/gql GraphQL API
API Endpoint panelbalonxfs[.]xyz/admin/api/api/rest REST API
API Endpoint panelbalonxfs[.]xyz/admin/api/api/token Authentication token endpoint
WebSocket Path /ws WebSocket command-and-control path on active Balonx phishing domains
Android Package sacred.explosion Malicious Android RAT package name
Android Main Class bxelllolzxqfmaszk1049 Main class associated with the malicious APK
Base64 C2 Host Field MTk2LjI1MS44NC4xMQ== Encoded Android RAT command-and-control host field
Base64 C2 Port Field Nzc3MQ== Encoded Android RAT command-and-control port field
Delivery Screen PROTECCION_BANCARIA Fake bank-protection screen used to distribute the malicious APK

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackHackerphishingSecurityThreat

Share Article

David kimber

David kimber

David is a penetration tester turned security journalist with expertise in mobile security, IoT vulnerabilities, and exploit development. As an OSCP-certified security professional, David brings hands-on technical experience to his reporting on vulnerabilities and security research. His articles often feature detailed technical analysis of exploits and provide actionable defense recommendations. David maintains an active presence in the security research community and has contributed to multiple open-source security tools.

Previous Post

China Hackers Use Malicious VHD Disguised as JPEG to Deploy QUICAgent Backdoor

Next Post

Leaked Stripe Merchant API Keys Expose Payment and Payout Capabilities

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Ransomware Gangs Impersonate Recovery Firms, Demand Up to $60,000
August 19, 2026
Critical macOS Screen Sharing Vulnerability Actively Exploited
August 19, 2026
MacSync Stealer Uses 30+ Domains to Steal Passwords and Sensitive Mac Data
August 19, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
David kimber
David kimber
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us