Researchers from Group-IB have detailed a large-scale Phishing-as-a-Service (PhaaS) operation called Balonx Sistema, which is actively targeting the customers of more than 20 financial institutions in Mexico. The platform equips low-skilled cybercriminals with a comprehensive toolkit for conducting financial fraud, including real-time phishing panels and a malicious Android RAT. The service was openly advertised on Facebook, and a significant operational security failure by the operators—leaving GitHub repositories exposed—allowed Group-IB to gain deep insight into the entire operation, including its infrastructure, affiliate network, and victims.
Balonx Sistema functions as a turnkey solution for financial fraud. Subscribers to the service gain access to a suite of tools designed to steal banking credentials and bypass two-factor authentication (2FA).
This combination of live phishing, a mobile RAT, and social engineering makes Balonx Sistema a highly effective tool for industrial-scale fraud, contributing to Mexico's status as a major target for banking malware in Latin America.
Group-IB's investigation, aided by the discovery of exposed GitHub repositories, revealed the technical underpinnings of the operation.
T1584.004 - Social Media Accounts).T1566 - Phishing combined with advanced session hijacking.T1417 - Input Capture to log keystrokes and T1426 - System Information Discovery to gather device details.T1412 - SMS-based 2FA Interception), which are then relayed to the fraudster via the C2 panel to complete fraudulent transactions.T1566 - PhishingT1204.002 - Malicious File (for the Android APK)T1417 - Input Capture (Mobile)T1412 - SMS-based 2FA Interception (Mobile)T1584.004 - Social Media AccountsBalonx Sistema significantly lowers the barrier to entry for committing sophisticated financial fraud. By packaging advanced tools into an easy-to-use service, it empowers a large number of low-skilled actors, amplifying the threat to Mexico's banking customers. The direct impact is financial loss for individuals and increased fraud-related costs for banks. The operation also erodes trust in digital banking channels and highlights the ongoing challenge of securing the mobile ecosystem against malware.
No specific file hashes, C2 domains, or IP addresses were provided in the source articles.
For financial institutions and security researchers:
update.apk, security.apkEducate banking customers to identify phishing attempts and to never download applications from untrusted sources.
Promote the use of phishing-resistant MFA, such as hardware tokens or app-based authenticators, over SMS.
Group-IB publishes its report on the Balonx Sistema PhaaS platform.

Cybersecurity professional with over 10 years of specialized experience in security operations, threat intelligence, incident response, and security automation. Expertise spans SOAR/XSOAR orchestration, threat intelligence platforms, SIEM/UEBA analytics, and building cyber fusion centers. Background includes technical enablement, solution architecture for enterprise and government clients, and implementing security automation workflows across IR, TIP, and SOC use cases.
CyberNetSec.io uses automation to assist source monitoring, deduplication, observable extraction, and structured intelligence generation. Published analysis follows human-defined editorial standards and adds defensive context including MITRE ATT&CK, D3FEND, STIX, and Sigma where applicable. Read our editorial policy.
Help others stay informed about cybersecurity threats
Every tactic, technique, and sub-technique used in this threat has been identified and mapped to the MITRE ATT&CK framework for consistent, actionable threat language.
Observables and indicators of compromise (IOCs) have been extracted and cataloged. Risk has been assessed and correlated with known threat actors and historical campaigns.
Detection rules, incident response steps, and D3FEND-aligned mitigation strategies are included so your team can act on this intelligence immediately.
Structured threat data is packaged as a STIX 2.1 bundle and can be visualized as an interactive graph — relationships between actors, malware, techniques, and indicators.
Sigma detection rules are derived from the threat techniques in this article and can be converted for deployment across any major SIEM or EDR platform.