Glossary
share:

Solutions that protect against video injection attacks where fraudsters bypass the device camera with synthetic video

A customer opens a new account in minutes. They upload their ID and complete a biometric check without raising a single red flag.

Except there was never a real person behind the camera. Instead, a fraudster used a synthetic video generated with AI and injected it directly into the onboarding session, bypassing the device camera. To the verification system, the video appeared authentic. To the business, the applicant looked like a genuine customer.

As deepfake technology becomes more accessible, these attacks are becoming more sophisticated and common. As such, businesses need defenses that can verify both the authenticity of the biometric check and the integrity of the device environment delivering it.

Solutions that protect against video injection attacks where fraudsters bypass the device camera with synthetic video include.

What is a video injection attack?

A video injection attack is a sophisticated form of fraud where an attacker bypasses a device's physical camera to feed a manipulated video stream directly into a broad range of applications. 

Fraudsters use several tools to execute these attacks:

  • Deepfake videos created using AI to mimic a target's facial movements and expressions
  • Face swap technology that overlays one person's features onto another's in real time
  • Pre-recorded videos of a genuine user that are replayed to satisfy liveness prompts
  • Synthetic identities that combine real and fabricated data to create entirely new, non-existent personas

The main difference lies in the method of delivery. In a presentation attack, the fraudster shows fake media to a physical camera. 

In an injection attack, they feed manipulated media directly into the device or software pipeline. This makes it much harder for basic sensors to detect the origin of the stream.

How video injection attacks work

Bypassing the device camera

Fraudsters often start by hijacking the link between the camera driver and the onboarding application to intercept the data stream. Once they control this connection, they perform a direct injection by inserting synthetic or manipulated video at the system level.

The onboarding platform then receives this injected content and processes it as a legitimate live feed from a physical environment.

Common attack methods include:

  • Virtual cameras: Software that emulates a webcam to broadcast pre-recorded or AI-generated files
  • Device emulators: Programs that simulate mobile hardware on a computer, allowing for easy file injection
  • Modified operating systems: Using rooted or jailbroken devices to bypass standard security permissions
  • Deepfake and face swap applications: Tools that generate realistic facial animations in real time
  • Replay attacks: Feeding a previously captured video of a genuine person back into the system

Read more: Deepfake fraud protection: Prevent ID and biometric spoofing

What to look for in a video injection attack detection solution

Camera and device integrity monitoring

A strong solution should have the ability to verify the integrity of the hardware and software connection. It needs to check if the camera being used is a physical component or a piece of software. This involves the detection of:

  • Non-standard virtual cameras
  • Emulators used to run mobile apps on desktops
  • System code modifications or "hooking" that intercepts data
  • Other indicators of device tampering

Behavioral and device intelligence

Effective detection goes beyond the camera lens by analyzing a broad spectrum of secondary signals.

For example, a sophisticated system evaluates device metadata to find inconsistencies between the reported hardware model and the operating system version. It may also use IP intelligence to flag high-risk locations or the active use of virtual private networks and anonymous proxies.

The software monitors behavioral patterns like typing cadence to identify the robotic input typical of automated scripts. Navigation patterns provide another layer of defense by spotting users who move through the onboarding journey too fast for a human to read the prompts.

Identifying these anomalies helps you catch fraudsters who may have a convincing deepfake but fail to mimic the technical footprint of a genuine customer.

Velocity and fraud intelligence

The platform should detect when:

  • The same face appears across different applications with different identity documents
  • The same physical document appears with multiple different faces attached to it
  • Previously seen fraudulent assets, like a specific deepfake file, are reused

Linking these biometric signals with broader fraud intelligence allows you to spot patterns that point toward coordinated attacks (rather than isolated incidents).

How we protect against video injection attacks

We’re a global identity technology provider that helps businesses connect safely with genuine customers while blocking sophisticated fraud. 

Our end-to-end identity verification solution, GBG Go, supports compliance and protects revenue by combining deep data with biometric verification and device-level security.

Detect device-level manipulation and injected media

Fraudsters often attempt to hijack the link between the camera driver and your application. We actively monitor the integrity of this hardware and software connection throughout the entire onboarding session to block the technical workarounds that drive modern identity fraud.

Our technology identifies non-standard virtual cameras and emulators that broadcast pre-recorded or AI-generated files instead of live footage. We also detect system code modifications or hooking that indicate a compromised device environment.

The system confirms whether a video stream originates from a legitimate physical lens or if it’s been manipulated at the software level.

Verify the person behind the biometric

To confirm the person behind the biometric, we use certified passive liveness testing that meets the highest ISO/IEC standards for presentation attack detection.

This technology analyzes a single high-resolution selfie for microscopic indicators of authenticity, such as skin elasticity and the specific way natural light reflects off a human eye.

Unlike active checks that require users to blink or smile, this passive approach eliminates friction by allowing customers to remain still during the process.

Connect biometric signals with fraud intelligence

Our platform analyzes secondary behavioral and device signals during the onboarding session to identify suspicious activity that biometrics alone might not catch.

For instance, we evaluate IP address indicators and device metadata alongside typing cadence and navigation behavior to spot the robotic anomalies that define automated fraud scripts.

Our system also uses velocity checks to identify when the same deepfake video or fraudulent document is reused across different applications.

David Thomas, Global Head of Product, Documents and Biometrics at GBG, explains that velocity is much more than just whether we have seen a person before. He notes that it’s about whether we have seen that face paired with a document carrying different information, or whether the same document is showing up repeatedly with different faces attached to it.

“This pattern is a telltale sign of fraud. The combination of biometric matching and velocity is what makes the difference,” he says.

Final thoughts

Modern identity fraud is essentially a race between AI and defense. By layering hardware integrity checks, behavioral intelligence, and high-resolution biometric verification, our platform can help ensure you are not just seeing a face, but verifying a genuine, trusted human being. 

This multi-layered approach allows you to scale global onboarding and meet strict regulatory requirements without increasing the risk of account takeovers or synthetic identity fraud.

FAQ: Video injection attacks

How can a business detect virtual camera software?

Detection involves monitoring the device environment during the session. Solutions check for virtual camera drivers, emulators and system-level modifications that attempt to inject media into the data stream. If the system detects that the input isn’t coming from a standard hardware camera, it can flag or block the application.

Why is passive liveness better for detecting injection attacks?

Passive liveness testing analyzes high-resolution images for organic signals like skin texture and light reflection that are difficult for synthetic media to mimic perfectly. Because it requires no prompted actions, it avoids the predictability that fraudsters often exploit when using pre-recorded videos to satisfy "blink" or "smile" requests.

What is the risk of using deepfakes in identity verification?

Deepfakes allow fraudsters to impersonate victims or create synthetic identities to open accounts, apply for credit, or take over existing services. Without injection attack detection, these AI-generated videos can appear authentic to standard biometric systems, leading to financial loss and regulatory penalties.

Can video injection be used for account takeover?

Yes. If a service uses biometric authentication for password resets or high-value transactions, a fraudster can use an injection attack to feed a deepfake of the account holder into the system to gain unauthorized access. Multi-dimensional monitoring, including device and behavioral signals, helps prevent this.

Get in touch with GBG

Request a demo