.webp?ssl=1)
Hackers are pairing AI-generated phone calls with fake banking pages to take over customer accounts, even when multi-factor authentication is enabled.
The campaign, tracked as Balonx Sistema, gives criminals a live view of a victim’s phishing session and lets them request information at the precise moment it is needed.
The operation targets more than 20 Mexican financial institutions and has collected credentials and financial data from over 1,100 people since at least October 2025.
It is built as a subscription service, lowering the barrier for affiliates who want to run banking scams at scale. It has individual and office plans, giving multiple operators controlled access to victim sessions and selected banking brands.
Analysts at Group-IB identified the platform after leaked GitHub repositories exposed parts of its operation, including its infrastructure and affiliate network.
Group-IB said in a report shared with Cyber Security News (CSN) that Balonx combines live phishing, an Android remote-access tool, and automated voice fraud.
The result is a blended attack that moves from an urgent call to a convincing website and, in some cases, a malicious mobile app. It shows why a code sent by text message is not always enough to stop a fraudster who is guiding the victim.
Hackers Use AI Voice Calls and Fake Banking Pages
Balonx uses a persistent WebSocket connection to keep the phishing page and the criminal’s control panel linked in real time.
After a target types banking credentials, the operator can relay them to the genuine bank site, trigger an MFA prompt, and immediately show a matching fake verification screen.
That timing is central to the scam. Victims may be asked for an SMS code, purchase-approval code, ATM PIN, card details, or a cardless-withdrawal code, all under the appearance of a bank check.
Balonx can present 14 different screen types, allowing an affiliate to change the story as a session develops and keep a victim moving through the requested steps.
The technique resembles phishing attacks bypass MFA by placing the attacker between the customer and the legitimate service rather than simply collecting a password.
This approach makes an ordinary security check appear genuine because the fraudulent page responds while the real bank session is active.
A separate CallFlow module makes the social engineering more convincing. It uses a language model, speech-to-text processing, and synthetic speech to conduct calls as a fabricated bank representative named Carolina.
The platform can run outbound campaigns without relying on a human operator for every conversation. This automation can make a suspicious call feel personal and responsive.
Recent coverage of automated bank support calls illustrates the same danger: a caller can steer a target toward a fake page, then use the interaction to obtain credentials or persuade them to install software.
Mobile Access Extends the Fraud
Balonx also distributes a Spyroid-based Android remote access trojan through a screen that poses as a bank-protection alert.
Once installed, the app can maintain contact with its command server and send screen content, keystrokes, SMS messages, and banking-app activity to the criminals.
Its persistent connection is designed not to time out, which can give an operator uninterrupted access after the initial deception succeeds.
This second stage turns an account-phishing attempt into a potential device takeover.
It follows a wider pattern seen in Android remote-control banking threats, where criminals use a fraudulent website or call to push an app outside an official store and gain deeper access to the phone.
Bank customers should end unexpected support calls and independently call the number printed on their card or shown in the official banking app.
They should never install an app suggested by a caller or an unverified website, and should treat requests for a PIN, CVV, or card scan as a warning sign.
The campaign also rotates domains, preserving data even after a fraudulent site is reported or removed.
Financial institutions can monitor related infrastructure, unusual WebSocket activity, and suspicious redirect chains. For high-value users, hardware security keys based on FIDO2 are more resistant to real-time relay attacks than SMS codes.
Anyone who believes they shared information should contact their bank through verified official banking channels immediately, reset credentials, and review recent transactions.
Indicators of compromise (IoCs):-
| Type | Indicator | Description |
|---|---|---|
| Domain | Aclaraciones-digital[.]online | Balonx campaign infrastructure |
| Domain | soporte-aclaracion[.]xyz | Balonx campaign infrastructure |
| Domain | balonx[.]online | Balonx campaign infrastructure |
| Domain | callbalonx[.]info | CallFlow AI vishing login portal |
| Domain | panelbalonxfs[.]xyz | CallFlow FreePBX backend and UCP |
| IP Address | 196.251.84[.]11 | Android RAT command-and-control server |
| Network Port | 7771/TCP | Android RAT command-and-control port |
| IP Address | 85.31.235[.]109 | CallFlow SIP server |
| Network Port | 5160/TCP | CallFlow SIP service port |
| API Endpoint | panelbalonxfs[.]xyz/admin/api/api/gql | GraphQL API |
| API Endpoint | panelbalonxfs[.]xyz/admin/api/api/rest | REST API |
| API Endpoint | panelbalonxfs[.]xyz/admin/api/api/token | Authentication token endpoint |
| WebSocket Path | /ws | WebSocket command-and-control path on active Balonx phishing domains |
| Android Package | sacred.explosion | Malicious Android RAT package name |
| Android Main Class | bxelllolzxqfmaszk1049 | Main class associated with the malicious APK |
| Base64 C2 Host Field | MTk2LjI1MS44NC4xMQ== | Encoded Android RAT command-and-control host field |
| Base64 C2 Port Field | Nzc3MQ== | Encoded Android RAT command-and-control port field |
| Delivery Screen | PROTECCION_BANCARIA | Fake bank-protection screen used to distribute the malicious APK |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Prevent incidents due to slow investigations. Power your Tier 1 with threat intelligence from 15K SOCs: Integrate TI Lookup in your SOC
The post Hackers Use AI Voice Calls and Fake Banking Pages to Bypass MFA and Steal Accounts appeared first on Cyber Security News.
Discover more from RSS Feeds Cloud
Subscribe to get the latest posts sent to your email.
