Re: KYC Bypass
KYC bypass tool sold on dark web and through Telegram channels are legit, but mixed in with a lot of scammers.
Here is how it works:
An operator uploads a passport-style photo (AI-generated or a leaked picture of a real person).
The app generates identity details and produces a passport image with that information.
From the original photo, it creates a deep⊗⊗⊗⊗ video of a 3D character performing actions (depending on the target service), often required during identity verification.
The tool then feeds both the document image and the deep⊗⊗⊗⊗ video into the verification pipeline through a camera emulator.
On the platform, it appears as if a real user is presenting a document and responding to prompts in real time.
In reality, the entire interaction is ⊗⊗⊗⊗.
But according to the video, the spoofing attempt was successful.
This is a classic example of an injection attack, there are others too.
Instead of processing a real camera input, the system receives synthetic media.
Given the current capabilities of GenAI and the wide availability of camera emulators, this threat becomes increasingly prevalent.
Convincing document photos can be produced in seconds. Realistic characters can be animated from a single reference image.
Binance, BBVA (Spain's second biggest bank), and Revolut say they are aware of KYC bypasses.
This technology exists and is not such a high cost.
I haven't needed this service yet so haven't done real deep research on it yet.
As they say, where there's a will there's a way.
|