AI-Powered Balonx Sistema PhaaS Harvests Credentials From Over 1,100 Banking Users
ID: d9f76bd0-2f03-54c4-89ab-1af2c9825861
STIX ID: report--d9f76bd0-2f03-54c4-89ab-1af2c9825861
Feed Name: GBHackers
Threat Score
Balonx Sistema is a Mexico-targeted Phishing-as-a-Service that has stolen credentials and financial data from over 1,100 banking users by combining live WebSocket phishing pages, a Spyroid-based Android RAT (BankProtect) with a C2 at 196.251.84.11:7771, and AI-powered voice-fraud (GPT-4o-mini, ElevenLabs, Whisper) to automate vishing; the service is centrally managed, subscription-based, and supports domain rotation and affiliate controls to scale and persist operations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
