Mobile deepfake attacks
Deepfake-enabled attacks are changing what mobile face authentication has to withstand. Across Asia, mobile-first banking, rapid digital onboarding, and fragmented device environments are creating the exact conditions these attacks exploit.
This playbook explains how those attacks work, why the real exposure sits in the device, runtime, and camera path behind the biometric check, and what banks can do to close the gap.
Mobile face authentication sits at the heart of how banks in Asia onboard customers, recover accounts, and approve high-risk transactions. It has also become a primary target, and not in the way most teams are still defending against.
Attackers do not need to fool the biometric model directly. They target the environment around it: the device, the camera pipeline, and the app runtime. First, a hostile device environment is established, a rooted or jailbroken handset, a virtual space, or a cloned banking app. Next, the camera path is replaced using tools like VCAM or VCAMSX, so the app receives injected synthetic content instead of a live feed. Then hooking and instrumentation frameworks, Frida, LSPosed, Objection, tamper with the session logic. The biometric check runs. The liveness result passes. The session moves forward. The fraud appears later.
Regional cases confirm the pattern. In Indonesia, virtual camera tooling was used to inject deepfakes into bank KYC flows. In Thailand, stolen photos were used to beat facial biometric checks. GoldPickaxe showed how mobile malware can combine biometric theft, app abuse, and fraud in a single operation.
Liveness detection inspects the frame it receives, not how that frame arrived. If the app and runtime behind the check are compromised, the result cannot be trusted regardless of model quality.
This playbook covers the layered control model banks need to close that gap, and where Promon Shield for Mobile™ fits in protecting the environment behind face authentication.
What you'll learn:
How deepfake-enabled attacks bypass mobile face authentication on real-world devices
Why attackers target the device, camera path, and runtime, not just the biometric check
What recent fraud cases across Indonesia, Thailand, and Vietnam reveal about mobile banking exposure
Why liveness and AI detection alone leave a gap in the app and runtime behind face-auth
Where banks are most exposed across onboarding, login, recovery, and step-up approval
How a layered control model adds device trust, app integrity, runtime protection, and usable evidence
Where Promon Shield for Mobile™ fits in protecting the environment behind face authentication
Is your mobile face-auth flow ready?
If your teams cannot confirm device trust at the moment of authentication, detect runtime tampering in-session, or explain what happened around a face-auth result, your app may be a blind spot in your fraud and compliance posture.
Download the playbook to find out how to close the gap.