New Phishing Kit Uses AI to Fully Automate Vishing Attacks

KnowBe4 Team | Sep 2, 2026

A new phishing kit is using generative AI to fully automate voice phishing (vishing) attacks, according to researchers at Group-IB.

The phishing platform, called “Balonx,” includes a module dubbed “CallFlow” that the researchers say “represents a fundamental evolution” in the phishing-as-a-service market. This module uses four commercial AI services to conduct the attacks: OpenAI’s GPT-4o-mini, ElevenLabs’s AI voice generator, OpenAI Voice, and OpenAI Whisper.

“When CallFlow contacts a victim, the conversation is conducted entirely by the LLM speaking through the synthetic voice of a fabricated bank representative named Carolina (the ElevenLabs voice profile),” Group-IB says. “The victim’s spoken responses are transcribed in real time by OpenAI Whisper, which feeds the transcript back to GPT-4o-mini to generate contextually appropriate follow-up responses. The interaction is indistinguishable from a human call-center operator to most victims.”

The Balonx phishing platform also allows human operators to monitor the attacks in real time, so they can step in if the AI runs into problems.

“The administrative interface of the CallFlow panel displays an operational dashboard showing active calls, daily call volume, success rates, calls in queue, active campaigns, total phone records in the database, and average call duration,” Group-IB says. “Investigation of the panel revealed targeted campaigns for several banks alongside a database of telephone numbers specifically related to one bank brand account, suggesting this database serves as a primary call list for the automated vishing system.” Balonx is currently targeting users in Mexico, but Group-IB expects this AI-driven vishing model to go global very soon.

“Vishing attacks have historically been limited by the availability of human operators,” the researchers write. “The CallFlow module eliminates that constraint entirely, enabling a single operator to run hundreds of simultaneous fraudulent calls without any human involvement in the conversation itself. As this architecture matures and spreads through criminal networks, financial institutions will face vishing attacks of unprecedented scale and linguistic quality.”

AI-native security awareness training can give your employees a healthy sense of suspicion so they can avoid falling for social engineering attacks. KnowBe4 empowers your workforce to make smarter security decisions every day. Over 70,000 organizations worldwide trust the KnowBe4 Platform to strengthen their security culture and reduce human risk.

Group-IB has the story: https://www.group-ib.com/blog/balonx-sistema-mexico-phaas/

See KnowBe4 Security Awareness Training in Action

See how you can efficiently safeguard your organization from sophisticated social engineering threats.

Request a Demo

Secure the Digital Workforce: Human + AI

KnowBe4 empowers the modern workforce to make smarter security decisions every day. Trusted by more than 70,000 organizations worldwide, KnowBe4 is the pioneer of digital workforce security, securing both AI agents and humans. The KnowBe4 Platform provides attack simulation and training, email and collaboration security, and agent security powered by AIDA (Artificial Intelligence Defense Agents) and a proprietary Risk Score. The platform leverages 15 years of behavioral data to combat advanced threats including social engineering, prompt injection, and shadow AI. By securing humans and agents, KnowBe4 leads the industry in workforce trust and defense.