🚨Balonx Sistema shows how Phishing-as-a-Service (PhaaS) is evolving into a multi-vector financial fraud operation targeting Mexican banking customers.
In our latest technical investigation, Group-IB uncovers how the operation combines:
🔹 Weekly PhaaS subscriptions targeting 20+ financial institutions (3,000–6,000 MXN/week)
🔹 1,100+ harvested credentials and financial records since October 2025
🔹 WebSocket-based real-time session hijacking with 14 screen types for MFA interception
🔹 Spyroid-based Android RAT (BankProtect) for persistent device control
🔹 AI-powered vishing using GPT-4o-mini, ElevenLabs, and OpenAI Whisper
🔹 350+ domains linked to the Balonx and Aclaraciones Bancarias campaigns
The investigation reveals how phishing, malware, and AI-driven social engineering are being integrated into a single criminal ecosystem with active domain rotation and centralized PostgreSQL infrastructure.
Read the full technical analysis.
#Phishing #FinancialFraud #CyberSecurity #MalwareThreats
Post #985
784

- 🔥 7
- 👏 2
- 👍 1