At a glance
| Actor or group | Mexico-based operator known as “balonx” and affiliates (alleged) |
| Activity type | Phishing-as-a-Service, Android RAT, AI-driven vishing |
| Targets | Customers of 20+ Mexican financial institutions |
| Scale | 1,100+ victims; about $99,384 USD claimed from 12 users; 350+ domains |
| Status | Reported by researchers; no arrests announced |
| Source | Group-IB |
TL;DR
Group-IB exposed a Mexican Phishing-as-a-Service platform called Balonx Sistema. It rents phishing tools by the week and targets more than 20 banks. Notably, it bundles an Android RAT and an AI-driven vishing module.
What happened
Group-IB analyzed Balonx Sistema after finding its landing pages. A leaked GitHub repository then opened the whole operation to view. That slip let analysts track victims and map the infrastructure.
The platform runs like a real software business. Affiliates register through a Telegram bot and pay weekly. Group-IB describes it as a “comprehensive cybercriminal enterprise” with tiered subscriptions. Prices run from 3,000 to 6,000 MXN per week.
Real-time phishing that beats MFA
Balonx does not just harvest passwords from a form. It keeps a live WebSocket link to the victim’s screen. As a result, the operator acts as a live man-in-the-middle. They can push 14 different fake screens on demand.
This design targets multi-factor authentication directly. The operator relays stolen credentials to the real bank site. When the bank sends a one-time code, a fake screen asks the victim for it. The victim hands the OTP straight to the attacker.
An Android RAT and AI voice fraud
The kit reaches past the browser. A fake “bank protection” alert pushes a malicious APK. That app is a commercial Android RAT built on the Spyroid framework. Once installed, it keeps a persistent connection for keylogging and screen capture.
A separate module named CallFlow adds automated voice fraud. It chains commercial AI tools into one calling pipeline. According to Group-IB, the module aims to replace “human call-center operators” entirely. A synthetic voice speaks while a language model drives the conversation.
Who is behind it
Group-IB attributes the platform to a Mexico-based operator using the handle “balonx.” A SuperAdmin approves each new affiliate. These findings come from researchers, not a court, so they remain allegations. No arrests have been announced.
Impact or scale
The numbers come from the platform’s own panel, so treat them as claims. Group-IB says the operation harvested credentials from more than 1,100 victims since October 2025. One panel view showed about $99,384 USD in earnings from just 12 users. Researchers also linked over 350 rotating domains to the campaign.
How to stay protected
Never install an app pushed by a security pop-up during online banking. Real banks never ask you to relay a one-time code to a live agent. Treat urgent verification prompts with suspicion. Install banking apps only from official stores. When a call feels off, hang up and dial your bank directly.
Support Our Threat Intelligence
Find our zero-day alerts and CVE reports helpful? Support our work today and unlock a 100% ad-free reading experience!