TGViewer
Group-IB Group-IB @group_ib · 2.52K subscribers
Post #985 784
🚨Balonx Sistema shows how Phishing-as-a-Service (PhaaS) is evolving into a multi-vector financial fraud operation targeting Mexican banking customers.

In our latest technical investigation, Group-IB uncovers how the operation combines:
🔹 Weekly PhaaS subscriptions targeting 20+ financial institutions (3,000–6,000 MXN/week)
🔹 1,100+ harvested credentials and financial records since October 2025
🔹 WebSocket-based real-time session hijacking with 14 screen types for MFA interception
🔹 Spyroid-based Android RAT (BankProtect) for persistent device control
🔹 AI-powered vishing using GPT-4o-mini, ElevenLabs, and OpenAI Whisper
🔹 350+ domains linked to the Balonx and Aclaraciones Bancarias campaigns

The investigation reveals how phishing, malware, and AI-driven social engineering are being integrated into a single criminal ecosystem with active domain rotation and centralized PostgreSQL infrastructure.

Read the full technical analysis.

#Phishing #FinancialFraud #CyberSecurity #MalwareThreats
  • 🔥 7
  • 👏 2
  • 👍 1
More from @group_ib
  1. Sep 23, 2026🚨Group-IB researchers have uncovered RemControl, a previously undocumented Android bankin…
  2. Sep 17, 2026🚨Group-IB Threat Intelligence has uncovered 29 new samples linked to the HEAVYGRAM and CR…
  3. Sep 14, 2026🚨 Inside the Smishing Triad’s Phishing Cockpit Group-IB’s latest research dives into JWR,…
  4. Sep 9, 2026🚨 Group-IB uncovers Vwork, a weaponized fork of the open-source Android app cloner Shelte…
  5. Sep 3, 2026🚨 Outsider Phishing Kit: a resilient PhaaS threat Group-IB researchers uncovered the Outs…
  6. Sep 1, 2026🚨 Cybercrime is evolving, and so is the underground economy behind it. Group-IB has uncov…
Threads Profile ViewerView any public Threads profile without an account.Open ThreadLook →Writing with AI? Make it sound human.Metric37 rewrites AI drafts so they read naturally. Free AI detector, 1,500 words free.Try Metric37 →