Balonx PhaaS Targets 20+ Mexican Banks With Real-Time MFA Bypass, Android RAT and AI Vishing
Brief
Mexico’s financial sector is facing a growing phishing threat from Balonx Sistema, a Phishing-as-a-Service (PhaaS) platform targeting more than 20 banks.
Group-IB researchers found that the operation combines real-time phishing, multi-factor authentication (MFA) interception, an Android remote access trojan (RAT) , and AI-powered voice scams.
The campaign reportedly harvested credentials and financial information from more than 1,100 victims since at least October 2025.
Balonx is designed as a subscription service, allowing affiliates with limited technical skills to run banking fraud campaigns through a centralized web panel.
The platform appears to be operated from Mexico and was promoted through Facebook groups associated with data trading and telemarketing fraud.
