Full Report
Group-IB expone una operación mexicana de PhaaS dirigida a más de 20 instituciones financieras, con capacidades de phishing en tiempo real, vishing con IA y RAT para dispositivos móviles.
Analysis Summary
# Threat Actor: Balonx (PhaaS Operation)
## Attribution & Identity
* **Actor Identification:** Balonx is a sophisticated Mexican-based Phishing-as-a-Service (PhaaS) operation.
* **Origin:** Highly attributed to Mexico based on language, targeting patterns, and technical infrastructure.
* **Business Model:** Operates as a provider of cybercrime tools, offering real-time phishing kits and automated voice services to other cybercriminals (affiliates).
## Activity Summary
Group-IB has exposed a large-scale operation by Balonx targeting over 20 financial institutions. The actor provides a comprehensive ecosystem for financial fraud, integrating real-time phishing panels with advanced AI-driven social engineering (Vishing) and mobile malware (RAT) to bypass Multi-Factor Authentication (MFA).
## Tactics, Techniques & Procedures
* **Real-time Phishing:** Utilization of interactive phishing panels that allow attackers to intercept credentials and OTPs in real-time.
* **AI-Enhanced Vishing:** Integration with AI tools (such as ElevenLabs/OpenAI) to generate realistic voice calls to victims to solicit sensitive information.
* **Adversary-in-the-Middle (AiTM):** Capturing session tokens and bypass MFA.
* **Social Engineering:** Posing as bank security or "Banking Protection" services to induce app downloads.
* **Android RAT Deployment:** Distributing malicious APKs to gain remote access to mobile devices.
* **MITRE ATT&CK IDs:**
* **T1566.002:** Phishing: Spearphishing Link
* **T1456:** Adversary-in-the-Middle
* **T1040:** Network Sniffing
* **T1471:** External Vishing
* **T1636.004:** Mobile Malware (Remote Access Tool)
## Targeting
* **Sectors:** Financial Services and Banking.
* **Geography:** Primarily Mexico and potentially broader LATAM regions.
* **Victims:** Over 20 specific financial institutions (unnamed in the snippet, but identified as major Mexican banks).
## Tools & Infrastructure
* **Malware:**
* **Balonx RAT:** An Android-based Remote Access Trojan distributed under the guise of "PROTECCION_BANCARIA" (Banking Protection).
* **Package Name:** `sacred.explosion`
* **Infrastructure:**
* **C2 Server:** `196.251.84[.]11` (Port 7771/TCP)
* **SIP/Vishing Server (CallFlow):** `85.31.235[.]109` (Port 5160/TCP)
* **API/Management Domains:**
* `panelbalonxfs[.]xyz`
* `panelbalonxfs[.]xyz/admin/api/api/gql`
* `panelbalonxfs[.]xyz/admin/api/api/rest`
* **Communication:** WebSockets used for C2 communication (`/ws` endpoint).
## Implications
Balonx represents an evolution in the LATAM threat landscape, moving from simple credential harvesting to complex, multi-vector attacks. The use of AI for vishing lowers the barrier for non-expert affiliates to conduct highly convincing social engineering, while the integration of mobile RATs ensures that even robust MFA defenses can be bypassed by controlling the victim's device directly.
## Mitigations
* **For Organizations:**
* Implement FIDO2-compliant hardware security keys to prevent AiTM phishing.
* Deploy Fraud Protection systems capable of detecting behavioral anomalies and automated remote access sessions.
* Monitor for unauthorized use of brand logos and domains via Digital Risk Protection (DRP) services.
* **For Users:**
* Never download "security" applications directly from links sent via SMS or email; only use official app stores.
* Be skeptical of unsolicited calls from "bank agents," even if the voice sounds natural or the caller ID is spoofed.
* Disable "Install from Unknown Sources" on Android devices.