Identity at Risk: AI Tools Outsmarting KYC Systems
Blog

Identity at Risk: AI Tools Outsmarting KYC Systems

OVERVIEW

Threat actors are actively leveraging AI-based synthetic media tools (Deepfakes) to systematically bypass mobile banking and digital platform selfie verification (liveness checks) during the Know Your Customer (KYC) onboarding process. A post on a prominent dark web forum details a step-by-step methodology using commercially available and niche AI tools to generate highly realistic facial images and video sequences, specifically to facilitate New Account Application and Card Fraud.

Image1.png

Post on a dark web forum

THREAT DETAILS & TECHNIQUES

Cybercriminals are sharing techniques that weaponize advancements in generative AI and facial synthesis to defeat biometric security controls. The threat targets the initial account opening phase where users are typically required to take a live selfie or record a short video to verify identity against submitted photo IDs.

THE MULTI-STEP ATTACK FLOW

Document Rendering: Fraudsters first use stolen or generated Personally Identifiable Information (PII) to create rendered or fraudulent government ID documents.

Image2.png

A threat actor manipulating the image of a driver’s license.

AI Image Synthesis: Specialized AI tools, such as Bylo AI1 are utilized to extract the face from the fraudulent ID and generate a realistic, high-quality photograph of the individual, often manipulated via prompts (e.g., “Take a selfie of a woman in an apartment”).

Image3.png

Extracted Image from a Driver’s License. Image after asking bylo.ai to “take a selfie of a woman in an apartment”.

Video Generation: The static image is animated into a video using tools like VideoMaker AI2 or advanced deepfake-creation platforms, including DeepFaceLab.3 This step is critical for defeating basic liveness checks that require movement (e.g., blinking, head turn). Below there is a short video example.

AIFaceBypass.mp4

Emulation and Delivery: The fabricated video is delivered to the mobile application’s camera input via Android emulators, such as Geelark Emulator4, LD Player5, or Memu6. This involves digitally inserting a pre-rendered deepfake video directly into the mobile app’s camera stream, making the synthetic video appear to be a live feed from a physical device. To execute this, the attackers must first resize the fraudulent video to match the emulator’s resolution. They then configure the emulator to accept an external video stream, either via a virtual camera tool like OBS7 (in Geelark) or by screen-capturing the video from the emulator’s own gallery (in LD Player/Memu) – effectively defeating the live check
protocols.

Image4.png

A threat actor running an Android emulator alongside video-editing software to stream a fabricated “video selfie” and bypass Stripe’s KYC selfie verification.

VARIOUS OTHER TOOLS AND INFRASTRUCTURE

The tactics and methods described above are supported and amplified by an ecosystem of off-the-shelf and niche tooling shared openly on underground forums. A comment on the original post made by another member of the underground forum references a dedicated Telegram channel, @facegentor, which offers a suite of deepfake products to support this type of fraud, including:

Face Video Generator: Using just one selfie and a short head-movement video, this tool lets fraudsters instantly generate a customized video.

Image5.png

Demonstration of a young woman (top left) using the Face Video Generator tool

Face Filter Tool: used for optical liveness detection with screen mirroring. When simulating optical liveness detection, a fraudster can use scrcpy8 to mirror the device’s screen and capture the color transitions that appear during the detection process. This allows you to record and analyze the red, yellow, and green flashes generated by the system as part of the liveness check.

Image6.png

Demonstration of the Face Filter Tool

Face Animator: Lets fraudsters use a webcam to drive images or videos in real time, making the person in the image or video perform actions such as opening the mouth, blinking, and turning the head left or right. This works in combination with a camera swap program to achieve KYC bypass.

Image7.png

Demonstration of the Face Animator Tool

Face Angle Generator: Lets fraudsters upload a reference face image, and by adjusting parameters (such as eyes, mouth, head pose, etc.), the app bulk-generates multi-angle images with different expressions and poses.

Image8.png

A fraudster using the Face Angle Generator tool

Camera Swap with Filter: Supports OBS and ManyCam9 streaming, this app can swap the camera input so that an app expecting live camera input instead receives a different video source (e.g., a prerecorded or synthesized video), and it can apply visual filters to that stream. They also have a separate tutorial available which guides fraudsters to install a “camera replacement” feature on their device. Using widely known methods to replace the phone camera’s video stream with OBS Studio or ManyCam9, the guide provides step-by-step instructions to help them set the optimal resolution, securely connect OBS to the phone, and configure the necessary permissions on both the computer and the phone.

Image9.png

A fraudster demonstrating the Camera Swap with Filter tool. Price List for available tools offered on Telegram

IMPACT

  • Bypass Identity Verification: Neutralize selfie and basic liveness checks, compromising the integrity of digital identity proofing.
  • Scale New Account Fraud (NAF): Enable the mass creation of fraudulent accounts, which are then used for money laundering, synthetic identity fraud, and carding.
  • Target Digital-First Platforms: Financial institutions relying heavily on mobile and digital onboarding are at heightened risk.
Table.png

Don’t forget

to Visit

Our Solutions

Read More1https://bylo.ai/, an “All-In-One AI Image Generator & Photo Editor” advertising GPT-4o, Gemini Nano Banana, Flux AI and other models for free online image creation and editing.
2https://videomaker.me/features/ai-360-spin
3https://apps.apple.com/us/app/deepfacelab-face-swap-editor/id1568914185
4https://www.geelark.com/
5https://www.ldplayer.net/, this tool allegedly contains malware based on some user’s comments
6https://www.memuplay.com/
7https://obsproject.com/
8An open-source tool that mirrors and controls an Android device’s screen from a computer (over USB or network). It shows the device display in a desktop window with very low latency and lets one interact with the phone using the keyboard/mouse.
9https://manycam.com/


About the Author(s)

Jessica Kelley is a e-crimes intelligence analyst with over a decade of experience spanning the U.S. Army, government, law enforcement, and the private sector.