Balonx Sistema PhaaS Campaign — AI Voice Calls and Fake Banking Pages Targeting Mexican Financial Institutions — Threadlinqs Intelligence
As of 2026-08-20, Balonx Sistema PhaaS Campaign — AI Voice Calls and Fake Banking Pages Targeting Mexican Financial Institutions is a high-severity threat intel threat attributed to Balonx, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 20 indicators of compromise.
Threat ID: TL-2026-2072 · Severity: HIGH · Status: ACTIVE · Category: THREAT_INTEL
Updated: 2026-08-20
Attribution: Balonx · FINANCIAL
Group-IB identified Balonx Sistema, a phishing-as-a-service (PhaaS) subscription platform targeting over 20 Mexican financial institutions. The campaign uses AI-generated voice calls (fabricated bank
Balonx Sistema is a highly structured, subscription-based Phishing-as-a-Service (PhaaS) platform developed by a Mexico-based cybercriminal operative and exposed by Group-IB following a critical operational security failure — leaked GitHub repositories that revealed hardcoded credentials, infrastructure details, and the full affiliate network. The platform operates as a criminal SaaS model, renting access to sophisticated phishing infrastructure on a weekly subscription basis (Individual: 3,000 MXN/week, ~$172 USD; Office: 6,000 MXN/week, ~$345 USD), with automated payment processing via the Bitso API (Mexican cryptocurrency exchange) and discount code promotional flexibility.
The platform combines three core technical capabilities into a single attack chain. First, the CallFlow AI vishing module uses GPT-4o-mini for conversational dialog generation, ElevenLabs for high-quality synthetic speech (voice profile 'Carolina'), and OpenAI Whisper for real-time speech-to-text transcription, all running on a FreePBX/Asterisk telephony backend (SIP server 85.31.235.109:5160/TCP). CallFlow completely automates outbound vishing calls, impersonating bank representatives without requiring human operators. Managers can covertly monitor active calls via Asterisk ChanSpy. Second, the WebSocket-based adversary-in-the-middle (AitM) phishing platform uses a persistent /ws endpoint on all active phishing domains to maintain a real-time bi-directional link between the victim's browser and the operator's control panel. The operator can dynamically push 14 distinct screen types (FOLIO, VALIDANDO, LOGIN, CODIGO for OTPs, NIP for ATM PINs, TARJETA for card details, SMS_COMPRA for purchase authorization, CANCELACION_RETIRO for cardless withdrawal codes, ESCANEAR_QR for physical card QR scans, PROTECCION_BANCARIA for APK delivery, PROTECCION_SALDO for balance capture, VERIFICACION_ID for ID/selfie theft via camera, MENSAJE for custom messages, and CANCELACION for completion). Affiliates can also pre-configure automated screen sequences via 'Mi Flujo Personal' (Personal Flows) that auto-execute, enabling less skilled operators to run sophisticated sessions. Third, an Android RAT built on the commercial Spyroid framework (package name: 'sacred.explosion', main class: 'bxelllolzxqfmaszk1049') is distributed through the PROTECCION_BANCARIA screen as a fake bank security alert. The RAT establishes a persistent TCP connection to C2 at 196.251.84.11:7771 with setSoTimeout(0) — the socket never times out — and captures keystrokes, SMS messages, screen content, and banking app interactions.
Campaign infrastructure spans 350+ identified domains since 2019, connected to a centralized Neon PostgreSQL database that preserves victim credentials, active sessions, and affiliate accounts across domain rotations. The platform is advertised openly on Facebook groups ('Base de Datos', 'Bases de datos Negocios Serios') and affiliates register via a Telegram bot with SuperAdmin approval (handle 'balonx'). The admin panel at /balonx path provides link generation, session management, per-bank targeting via allowedBanks permission matrix, credential display, and credit card information visibility. The operator maintains a hierarchical structure with Admin, Manager, and Executive roles, with Executive authentication via one-time passwords sent through Telegram. Estimated earnings from the operation are ~$1,728,000 MXN (~$99,384 USD), with 12 registered steady scammers in the admin panel. The campaign targets Banamex and at least 20 other Mexican financial institutions.
Target sectors: finance, banking
Target regions: mexico, Latin America
Timeline
- Earliest domain registration linked to the Aclaraciones Bancarias campaign lineage, indicating the broader infrastructure spans multiple related operations predating Balonx
- GitHub repository activity marks the beginning of Balonx PhaaS platform development, including the CallFlow AI vishing module and WebSocket AitM phishing kit
- First observed credential harvesting by Balonx affiliates; 1,100+ victims begin accumulating across 20+ Mexican financial institutions
- Hardcoded reference date in the Balonx PhaaS platform marking the commercial launch of the subscription-based phishing service
- Group-IB publishes comprehensive Balonx Sistema analysis following discovery of leaked GitHub repositories exposing hardcoded credentials, infrastructure, and affiliate network
- Campaign remains active with continuous domain rotation; affiliates continue targeting Mexican financial institutions; no known takedown of core infrastructure
Update History
- 2026-08-20 — tweetfeed.live community intel: New TL_OSINT_Scan community intel: 1 newly-corroborated indicator(s).
Detections & IOCs
As of 2026-09-06, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 20 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
THREAT_INTEL, HIGH, threat intelligence, cybersecurity, T1566.004, T1566.002, T1684.001, T1204.002, T1111, T1539, T1557, T1598.003, T1071.001, T1573.002