Hackers Use AI Voice Calls and Fake Banking Pages to Bypass MFA and Steal Accounts

Hackers Use AI Voice Calls and Fake Banking Pages to Bypass MFA and Steal Accounts

Hackers are pairing AI-generated phone calls with fake banking pages to take over customer accounts, even when multi-factor authentication is enabled.

The campaign, tracked as Balonx Sistema, gives criminals a live view of a victim’s phishing session and lets them request information at the precise moment it is needed.

The operation targets more than 20 Mexican financial institutions and has collected credentials and financial data from over 1,100 people since at least October 2025.

It is built as a subscription service, lowering the barrier for affiliates who want to run banking scams at scale. It has individual and office plans, giving multiple operators controlled access to victim sessions and selected banking brands.

Analysts at Group-IB identified the platform after leaked GitHub repositories exposed parts of its operation, including its infrastructure and affiliate network. 

Landing page of the Balonx Sistema PhaaS kit (Source - Group-IB)
Landing page of the Balonx Sistema PhaaS kit (Source – Group-IB)

Group-IB said in a report shared with Cyber Security News (CSN) that Balonx combines live phishing, an Android remote-access tool, and automated voice fraud.

The result is a blended attack that moves from an urgent call to a convincing website and, in some cases, a malicious mobile app. It shows why a code sent by text message is not always enough to stop a fraudster who is guiding the victim.

Hackers Use AI Voice Calls and Fake Banking Pages

Balonx uses a persistent WebSocket connection to keep the phishing page and the criminal’s control panel linked in real time.

After a target types banking credentials, the operator can relay them to the genuine bank site, trigger an MFA prompt, and immediately show a matching fake verification screen.

That timing is central to the scam. Victims may be asked for an SMS code, purchase-approval code, ATM PIN, card details, or a cardless-withdrawal code, all under the appearance of a bank check.

Balonx can present 14 different screen types, allowing an affiliate to change the story as a session develops and keep a victim moving through the requested steps.

The technique resembles phishing attacks bypass MFA by placing the attacker between the customer and the legitimate service rather than simply collecting a password.

Extract of core JavaScript file of Balonx Sistema PhaaS (Source - Group-IB)
Extract of core JavaScript file of Balonx Sistema PhaaS (Source – Group-IB)

This approach makes an ordinary security check appear genuine because the fraudulent page responds while the real bank session is active.

A separate CallFlow module makes the social engineering more convincing. It uses a language model, speech-to-text processing, and synthetic speech to conduct calls as a fabricated bank representative named Carolina.

The platform can run outbound campaigns without relying on a human operator for every conversation. This automation can make a suspicious call feel personal and responsive.

Recent coverage of automated bank support calls illustrates the same danger: a caller can steer a target toward a fake page, then use the interaction to obtain credentials or persuade them to install software.

Mobile Access Extends the Fraud

Balonx also distributes a Spyroid-based Android remote access trojan through a screen that poses as a bank-protection alert.

Once installed, the app can maintain contact with its command server and send screen content, keystrokes, SMS messages, and banking-app activity to the criminals.

Its persistent connection is designed not to time out, which can give an operator uninterrupted access after the initial deception succeeds.

This second stage turns an account-phishing attempt into a potential device takeover.

It follows a wider pattern seen in Android remote-control banking threats, where criminals use a fraudulent website or call to push an app outside an official store and gain deeper access to the phone.

Bank customers should end unexpected support calls and independently call the number printed on their card or shown in the official banking app.

C2 IP direction in the code of the APK (Source - Group-IB)
C2 IP direction in the code of the APK (Source – Group-IB)

They should never install an app suggested by a caller or an unverified website, and should treat requests for a PIN, CVV, or card scan as a warning sign.

The campaign also rotates domains, preserving data even after a fraudulent site is reported or removed.

Financial institutions can monitor related infrastructure, unusual WebSocket activity, and suspicious redirect chains. For high-value users, hardware security keys based on FIDO2 are more resistant to real-time relay attacks than SMS codes.

Anyone who believes they shared information should contact their bank through verified official banking channels immediately, reset credentials, and review recent transactions.

Indicators of compromise (IoCs):-

TypeIndicatorDescription
DomainAclaraciones-digital[.]onlineBalonx campaign infrastructure
Domainsoporte-aclaracion[.]xyzBalonx campaign infrastructure
Domainbalonx[.]onlineBalonx campaign infrastructure
Domaincallbalonx[.]infoCallFlow AI vishing login portal
Domainpanelbalonxfs[.]xyzCallFlow FreePBX backend and UCP
IP Address196.251.84[.]11Android RAT command-and-control server
Network Port7771/TCPAndroid RAT command-and-control port
IP Address85.31.235[.]109CallFlow SIP server
Network Port5160/TCPCallFlow SIP service port
API Endpointpanelbalonxfs[.]xyz/admin/api/api/gqlGraphQL API
API Endpointpanelbalonxfs[.]xyz/admin/api/api/restREST API
API Endpointpanelbalonxfs[.]xyz/admin/api/api/tokenAuthentication token endpoint
WebSocket Path/wsWebSocket command-and-control path on active Balonx phishing domains
Android Packagesacred.explosionMalicious Android RAT package name
Android Main Classbxelllolzxqfmaszk1049Main class associated with the malicious APK
Base64 C2 Host FieldMTk2LjI1MS44NC4xMQ==Encoded Android RAT command-and-control host field
Base64 C2 Port FieldNzc3MQ==Encoded Android RAT command-and-control port field
Delivery ScreenPROTECCION_BANCARIAFake bank-protection screen used to distribute the malicious APK

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Prevent incidents due to slow investigations. Power your Tier 1 with threat intelligence from 15K SOCs: Integrate TI Lookup in your SOC

The post Hackers Use AI Voice Calls and Fake Banking Pages to Bypass MFA and Steal Accounts appeared first on Cyber Security News.


Discover more from RSS Feeds Cloud

Subscribe to get the latest posts sent to your email.

Discover more from RSS Feeds Cloud

Subscribe now to keep reading and get access to the full archive.

Continue reading