Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Hackers Exploit AI and Fake Banking Sites to Bypass MFA

Hackers Exploit AI and Fake Banking Sites to Bypass MFA

Posted on August 20, 2026 By CWS

Cybercriminals are employing artificial intelligence to orchestrate sophisticated attacks on financial institutions, specifically targeting customer accounts protected by multi-factor authentication (MFA). A newly identified campaign leverages AI-generated voice calls along with counterfeit banking websites to breach security layers and gain unauthorized access.

Innovative Phishing Tactics Threaten Banks

Dubbed Balonx Sistema, this operation provides attackers with real-time access to a victim’s phishing session. By interacting at critical moments, hackers can extract sensitive information more effectively. The campaign has been linked to over 20 Mexican banks and has compromised the credentials of more than 1,100 individuals since October 2025.

The scheme is designed as a subscription service, simplifying access for affiliates keen to execute large-scale banking scams. Options include individual and office plans, allowing multiple operators to manage victim sessions under various banking brands.

Technical Insights into Balonx Sistema

According to analysts at Group-IB, the platform’s infrastructure and affiliate network were uncovered through leaked GitHub repositories. Balonx Sistema merges live phishing with an Android remote-access tool and automated voice scams, creating a seamless attack progression from phone call to web interaction, and sometimes to malicious mobile apps.

Utilizing a persistent WebSocket connection, the phishing sites remain synchronized with the attackers’ control panel. When victims input their banking details, hackers can prompt MFA requests and present fraudulent verification screens, making the attack appear legitimate.

Defensive Measures and Recommendations

The campaign includes a CallFlow module that enhances social engineering techniques. This module uses AI to simulate calls from a bank representative, making interactions appear authentic without human operators.

Balonx Sistema extends its reach by distributing a Spyroid-based Android remote access trojan through fake security alerts. Once installed, the app maintains a connection with the attackers, transmitting data such as keystrokes and SMS messages.

To safeguard against these threats, customers should independently verify any unexpected bank communications by contacting their financial institutions directly. Additionally, they should avoid downloading apps from unofficial sources and be wary of requests for sensitive information such as PINs and CVVs.

Financial institutions are advised to monitor for suspicious activities, such as unusual WebSocket connections and redirect chains. For high-security users, hardware keys based on FIDO2 standards offer better protection against these sophisticated relay attacks than traditional SMS codes.

Anyone suspecting they have been targeted should promptly contact their bank, change their credentials, and review their recent transaction history for unauthorized activities.

Cyber Security News Tags:AI phishing, AI voice calls, Android RAT, Balonx Sistema, banking scams, CallFlow module, cyber threats, Cybersecurity, fake banking pages, financial fraud, Group-IB, MFA bypass, phishing attacks, social engineering, Spyroid

Post navigation

Previous Post: Chinese Hackers Employ JPEG Disguise to Deploy Malware
Next Post: Airlock Digital Achieves IRAP PROTECTED Assessment

Related Posts

How To Get Real-Time IOCs From Incidents Across 15K SOCs  How To Get Real-Time IOCs From Incidents Across 15K SOCs  Cyber Security News
5 Actionable Tactics for SOC Analysts 5 Actionable Tactics for SOC Analysts Cyber Security News
Magecart Hackers Exploit 100 Domains to Steal Card Data Magecart Hackers Exploit 100 Domains to Steal Card Data Cyber Security News
Multiple vulnerabilities in Cisco Unified CCX Allow Attackers to Execute Arbitrary Commands Multiple vulnerabilities in Cisco Unified CCX Allow Attackers to Execute Arbitrary Commands Cyber Security News
New Botnet Hijacks 9,000 ASUS Routers & Enables SSH Access by Injecting Public Key New Botnet Hijacks 9,000 ASUS Routers & Enables SSH Access by Injecting Public Key Cyber Security News
New Variant of The XCSSET Malware Attacking macOS App Developers New Variant of The XCSSET Malware Attacking macOS App Developers Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • South Korea Initiates Security Overhaul After Bank Data Breaches
  • China-Linked TA419 Targets U.S. AI Experts with Phishing
  • Key Arrest in ShinyHunters Case Aids FBI Investigation
  • Vercel Unveils KVM Zero-Day Flaw, Rewards Researcher $50K
  • ShinyHunters Suspect in Jordan Assists FBI in Hack Probe

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • October 2026
  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • South Korea Initiates Security Overhaul After Bank Data Breaches
  • China-Linked TA419 Targets U.S. AI Experts with Phishing
  • Key Arrest in ShinyHunters Case Aids FBI Investigation
  • Vercel Unveils KVM Zero-Day Flaw, Rewards Researcher $50K
  • ShinyHunters Suspect in Jordan Assists FBI in Hack Probe

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark