logo

AI-Powered Balonx Sistema PhaaS Harvests Credentials From Over 1,100 Banking Users

ID: d9f76bd0-2f03-54c4-89ab-1af2c9825861

STIX ID: report--d9f76bd0-2f03-54c4-89ab-1af2c9825861

Feed Name: GBHackers

Threat Score
78/100

Date Published: 2026-08-26

Date Updated: 2026-08-26

Author: Mayura Kathir

...
...

Balonx Sistema is a Mexico-targeted Phishing-as-a-Service that has stolen credentials and financial data from over 1,100 banking users by combining live WebSocket phishing pages, a Spyroid-based Android RAT (BankProtect) with a C2 at 196.251.84.11:7771, and AI-powered voice-fraud (GPT-4o-mini, ElevenLabs, Whisper) to automate vishing; the service is centrally managed, subscription-based, and supports domain rotation and affiliate controls to scale and persist operations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.