Hackers Exploit AI Voice Calls to Bypass MFA and Steal Bank Accounts

Cybercriminals are increasingly leveraging artificial intelligence to orchestrate sophisticated phishing attacks that circumvent multi-factor authentication (MFA) and compromise bank accounts. A recent campaign, identified as Balonx Sistema, exemplifies this trend by combining AI-generated voice calls with counterfeit banking websites to deceive victims into divulging sensitive information.

Operating since at least October 2025, Balonx Sistema has targeted over 20 Mexican financial institutions, amassing credentials and financial data from more than 1,100 individuals. The platform functions as a subscription-based service, offering various plans that enable multiple operators to conduct banking scams at scale. This model significantly lowers the entry barrier for affiliates seeking to exploit banking customers.

Real-Time Phishing and AI-Driven Calls

Balonx Sistema employs a persistent WebSocket connection to synchronize the phishing page with the attacker’s control panel in real time. When a victim enters their banking credentials on the fraudulent site, the attacker can immediately relay this information to the legitimate bank, triggering an MFA prompt. Simultaneously, the victim is presented with a fake verification screen that mirrors the bank’s interface, prompting them to enter the MFA code.

This method allows attackers to request various sensitive details, including SMS codes, purchase approval codes, ATM PINs, card information, and cardless withdrawal codes, all under the guise of legitimate bank verification processes. The platform offers 14 different screen types, enabling affiliates to adapt the narrative as the interaction progresses and guide victims through the required steps.

To enhance the deception, Balonx Sistema incorporates a module named CallFlow, which utilizes a language model, speech-to-text processing, and synthetic speech to conduct automated calls. These calls, made by a fabricated bank representative named Carolina, add a layer of authenticity to the scam, making the fraudulent communication appear personal and convincing.

Mobile Device Compromise

Beyond phishing and voice calls, Balonx Sistema distributes an Android remote access trojan (RAT) disguised as a bank protection alert. Once installed, this Spyroid-based RAT maintains continuous communication with its command server, transmitting screen content, keystrokes, SMS messages, and banking app activities to the attackers. This persistent connection grants the attacker uninterrupted access to the compromised device, escalating the threat from account phishing to full device takeover.

To mitigate such risks, bank customers are advised to terminate unexpected support calls and independently contact their bank using the official phone number provided on their bank card or within the official banking app.

The emergence of platforms like Balonx Sistema underscores the evolving nature of cyber threats, where attackers increasingly exploit AI technologies to enhance the effectiveness and scalability of their operations. This development highlights the necessity for continuous advancements in security measures and heightened vigilance among consumers to counteract these sophisticated attacks.