Balonx Sistema PhaaS Campaign — AI Voice Calls and Fake Banking Pages Targeting Mexican Financial Institutions

Balonx Sistema PhaaS Campaign (TL-2026-2072), also tracked as Aclaraciones Bancarias campaign, is a high-severity tracked intrusion set, first published 2026-08-19 and last reviewed 2026-08-20. It is attributed to Balonx with high confidence, affects Banamex Online Banking, maps to 13 MITRE ATT&CK techniques (T1071.001, T1111, T1204.002), and is covered by 9 detection rules and 20 indicators of compromise.

Key facts for TL-2026-2072

Threat ID
TL-2026-2072
Also known as
Aclaraciones Bancarias campaign
Severity
HIGH
Status
ACTIVE
Category
THREAT_INTEL
First published
2026-08-19
Last reviewed
2026-08-20
Attribution
Balonx
Attribution confidence
HIGH
Motivation
FINANCIAL
Target sectors
finance, banking
Target regions
mexico, Latin America
Detection rules
9
Indicators of compromise
20
Updates
2026-08-20

Malware and tooling in Balonx Sistema PhaaS Campaign

Malware and tooling: Spyroid, CallFlow, WebSocket AitM Relay

Group-IB identified Balonx Sistema, a phishing-as-a-service (PhaaS) subscription platform targeting over 20 Mexican financial institutions. The campaign uses AI-generated voice calls (fabricated bank representative 'Carolina'), real-time adversary-in-the-middle phishing via WebSocket-connected fake banking pages, and an Android RAT (Spyroid-based, package 'sacred.explosion') distributed as a fake bank-protection screen. Credentials and data have been collected from over 1,100 victims since at least October 2025.

How Balonx Sistema PhaaS Campaign works

Balonx Sistema is a highly structured, subscription-based Phishing-as-a-Service (PhaaS) platform developed by a Mexico-based cybercriminal operative and exposed by Group-IB following a critical operational security failure — leaked GitHub repositories that revealed hardcoded credentials, infrastructure details, and the full affiliate network. The platform operates as a criminal SaaS model, renting access to sophisticated phishing infrastructure on a weekly subscription basis (Individual: 3,000 MXN/week, ~$172 USD; Office: 6,000 MXN/week, ~$345 USD), with automated payment processing via the Bitso API (Mexican cryptocurrency exchange) and discount code promotional flexibility.

The platform combines three core technical capabilities into a single attack chain. First, the CallFlow AI vishing module uses GPT-4o-mini for conversational dialog generation, ElevenLabs for high-quality synthetic speech (voice profile 'Carolina'), and OpenAI Whisper for real-time speech-to-text transcription, all running on a FreePBX/Asterisk telephony backend (SIP server 85.31.235.109:5160/TCP). CallFlow completely automates outbound vishing calls, impersonating bank representatives without requiring human operators. Managers can covertly monitor active calls via Asterisk ChanSpy. Second, the WebSocket-based adversary-in-the-middle (AitM) phishing platform uses a persistent /ws endpoint on all active phishing domains to maintain a real-time bi-directional link between the victim's browser and the operator's control panel. The operator can dynamically push 14 distinct screen types (FOLIO, VALIDANDO, LOGIN, CODIGO for OTPs, NIP for ATM PINs, TARJETA for card details, SMS_COMPRA for purchase authorization, CANCELACION_RETIRO for cardless withdrawal codes, ESCANEAR_QR for physical card QR scans, PROTECCION_BANCARIA for APK delivery, PROTECCION_SALDO for balance capture, VERIFICACION_ID for ID/selfie theft via camera, MENSAJE for custom messages, and CANCELACION for completion). Affiliates can also pre-configure automated screen sequences via 'Mi Flujo Personal' (Personal Flows) that auto-execute, enabling less skilled operators to run sophisticated sessions. Third, an Android RAT built on the commercial Spyroid framework (package name: 'sacred.explosion', main class: 'bxelllolzxqfmaszk1049') is distributed through the PROTECCION_BANCARIA screen as a fake bank security alert. The RAT establishes a persistent TCP connection to C2 at 196.251.84.11:7771 with setSoTimeout(0) — the socket never times out — and captures keystrokes, SMS messages, screen content, and banking app interactions.

Campaign infrastructure spans 350+ identified domains since 2019, connected to a centralized Neon PostgreSQL database that preserves victim credentials, active sessions, and affiliate accounts across domain rotations. The platform is advertised openly on Facebook groups ('Base de Datos', 'Bases de datos Negocios Serios') and affiliates register via a Telegram bot with SuperAdmin approval (handle 'balonx'). The admin panel at /balonx path provides link generation, session management, per-bank targeting via allowedBanks permission matrix, credential display, and credit card information visibility. The operator maintains a hierarchical structure with Admin, Manager, and Executive roles, with Executive authentication via one-time passwords sent through Telegram. Estimated earnings from the operation are ~$1,728,000 MXN (~$99,384 USD), with 12 registered steady scammers in the admin panel. The campaign targets Banamex and at least 20 other Mexican financial institutions.

MITRE ATT&CK techniques used in TL-2026-2072

Command and Control

T1071.001 Application Layer Protocol: Web Protocols; T1573.002 Asymmetric Cryptography

Credential Access

T1111 Multi-Factor Authentication Interception; T1539 Steal Web Session Cookie

Execution

T1204.002 User Execution: Malicious File

Collection

T1557 Adversary-in-the-Middle

Initial Access

T1566.002 Spearphishing Link; T1566.004 Spearphishing Voice

Resource Development

T1583.001 Acquire Infrastructure: Domains; T1586.001 Compromise Accounts: Social Media Accounts; T1588.002 Obtain Capabilities: Tool

reconnaissance

T1598.003 Phishing for Information: Spearphishing Link

stealth

T1684.001 Impersonation

Affected products and versions in Balonx Sistema PhaaS Campaign

  • Banamex — Online Banking
    Vulnerable versions: all
  • Multiple Mexican Financial Institutions — Online Banking
    Vulnerable versions: 20+ institutions targeted

Remediation for Balonx Sistema PhaaS Campaign

Immediate actions

  • Block all known Balonx infrastructure domains and IPs at perimeter (196.251.84.11, 85.31.235.109, aclaraciones-digital.online, soporte-aclaracion.xyz, balonx.online, callbalonx.info, panelbalonxfs.xyz)
  • Block port 7771/TCP and 5160/TCP outbound at network perimeter
  • Issue customer alerts about impersonation calls from 'Carolina' and fake bank protection APK installation requests
  • Monitor for /ws endpoint connections to known phishing domains in web proxy logs
  • Block panelbalonxfs.xyz API endpoints (GraphQL, REST, auth token) at network level

Workarounds

  • End unexpected calls claiming to be from the bank; independently call the number on the back of the card or official banking app
  • Never install APK files suggested by callers or unverified websites
  • Treat any request for PIN, CVV, card scan, or remote APK installation as a warning sign
  • Enable multi-factor authentication with FIDO2 security keys where available instead of SMS-based OTP

Longer-term hardening

  • Deploy FIDO2 hardware security keys for high-value customers to defeat real-time AitM relay attacks
  • Implement behavioral detection for WebSocket-based AitM phishing patterns
  • Establish continuous monitoring for domain registrations matching Aclaraciones Bancarias naming patterns
  • Deploy Endpoint Detection and Response (EDR) on mobile devices with Android RAT behavior detection
  • Implement SMS-based suspicious activity monitoring for account takeovers
  • Collaborate with Mexican financial sector CERT for cross-institution threat sharing

Timeline of Balonx Sistema PhaaS Campaign

  • Earliest domain registration linked to the Aclaraciones Bancarias campaign lineage, indicating the broader infrastructure spans multiple related operations predating Balonx
  • GitHub repository activity marks the beginning of Balonx PhaaS platform development, including the CallFlow AI vishing module and WebSocket AitM phishing kit
  • First observed credential harvesting by Balonx affiliates; 1,100+ victims begin accumulating across 20+ Mexican financial institutions
  • Hardcoded reference date in the Balonx PhaaS platform marking the commercial launch of the subscription-based phishing service
  • Campaign remains active with continuous domain rotation; affiliates continue targeting Mexican financial institutions; no known takedown of core infrastructure
  • Group-IB publishes comprehensive Balonx Sistema analysis following discovery of leaked GitHub repositories exposing hardcoded credentials, infrastructure, and affiliate network

Update history for TL-2026-2072

  • 2026-08-20 — tweetfeed.live community intel: New TL_OSINT_Scan community intel: 1 newly-corroborated indicator(s).

Sources cited for Balonx Sistema PhaaS Campaign

Threats related to Balonx Sistema PhaaS Campaign

Detection coverage for TL-2026-2072

As of 2026-08-20, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2072 across Splunk SPL, Microsoft KQL and Sigma, covering 20 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats