TL;DR: Native virtual camera attacks rose 2,665% in 2024 and reached 785 weekly incidents in Q2, according to iProov’s 2025 Threat Intelligence Report, showing how software-level camera interception can bypass conventional device checks and feed synthetic video into identity verification systems. Traditional liveness and root-detection controls are no longer enough when the attack operates inside standard permissions and intact metadata.
At a glance
What this is: iProov’s analysis shows that native virtual camera attacks can feed synthetic video into remote identity verification without rooted devices or obvious operating-system alarms.
Why it matters: This matters because identity teams cannot treat remote verification as purely a liveness problem; they have to govern the full capture path, device integrity, and fraud detection together.
By the numbers:
- iProov’s iSOC data recorded 785 weekly attack incidents at peak activity in Q2 2024.
Context
Remote identity verification depends on a simple assumption: the camera feed reaching the verifier is the same feed produced by the real device camera. Native virtual camera attacks break that assumption by inserting software between the camera hardware and the application, while staying inside standard permissions and intact metadata.
For IAM, identity proofing, and fraud teams, this is not just a biometric issue. It is a trust-chain problem across device permissions, capture integrity, and liveness validation, which means conventional root checks and challenge-response steps can be necessary but not sufficient.
iProov’s analysis places the threat in a maturation phase rather than an experimental one. The article describes a shift from niche tooling to broadly accessible apps, including distribution through mainstream app stores, which makes the control problem operational rather than theoretical.
Key questions
Q: What breaks when native virtual camera attacks bypass remote identity checks?
A: What breaks is the assumption that a verified camera session proves the person behind it is real. When software can substitute synthetic video inside standard permissions, the identity decision is no longer based on origin integrity. Remote proofing flows need to treat the camera stream as evidence that must be validated, not trusted by default.
Q: Why do native virtual camera attacks create risk even when devices are not rooted?
A: They abuse normal operating-system permissions rather than depending on full device compromise. That means root detection, jailbreak checks, and basic device posture controls can all return clean while the feed is still manipulated. Teams should therefore evaluate capture provenance and liveness integrity as separate trust questions.
Q: How can security teams tell whether liveness checks are too predictable?
A: If the same challenge-response pattern can be replayed by synthetic media, the control is too predictable. Repeated prompts, fixed motion templates, and static response timing are the signals that attackers can learn. Teams should test whether a fraudulent stream can satisfy the flow without any live sensor evidence.
Q: Should organisations combine biometric verification with endpoint telemetry for remote onboarding?
A: Yes. Biometric signals tell you whether the user interaction looks live, while endpoint telemetry tells you whether the capture path is trustworthy. Either one on its own is incomplete. The practical standard is to combine proofing, device integrity, and real-time monitoring before accepting high-risk identity decisions.
Technical breakdown
How native virtual cameras intercept the camera stream
A native virtual camera is software that runs on the device and positions itself between the physical camera and the application asking for video. Because it requests ordinary camera permissions, the operating system sees a normal permission grant rather than suspicious privilege escalation. Once active, the app can substitute the live feed with deepfakes, prerecorded video, or other synthetic imagery while preserving the appearance of a valid stream. The security problem is that the fraud happens below the application layer, where conventional identity verification logic often assumes the feed itself is trustworthy.
Practical implication: Treat video capture as an attested control surface, not just an application input.
Why root detection and metadata checks miss this attack
These attacks do not require rooted or jailbroken devices, so controls that rely on abnormal device state will miss a large part of the threat. They also preserve authentic-looking metadata and device characteristics, which defeats verification logic that expects anomalies in headers, permissions, or device posture. In practice, the attacker is not breaking into the device in the classic sense. They are abusing legitimate operating-system behavior to make fraudulent content look native, which shifts the detection problem from compromise to provenance.
Practical implication: Validate the provenance of the video stream itself, not only device state around it.
Why active liveness alone is not enough
Active liveness checks assume that if a user performs a prompted action such as blinking or turning, the feed is live. Native virtual camera tools can mirror those prompts with synthetic imagery, so the control becomes predictable and therefore replayable. Passive liveness and dynamic challenge patterns reduce that predictability, but the broader lesson is that identity verification must combine liveness, real-time signal analysis, and device integrity into one decision path. This is where the fraud domain and the cybersecurity domain meet.
Practical implication: Use liveness as one signal in a layered decision, not as the sole trust decision.
Threat narrative
Attacker objective: The attacker wants to impersonate a real person convincingly enough to defeat remote identity verification and gain fraudulent access or onboarding approval.
- Entry occurs when the user installs a camera or video app that requests standard permissions, sometimes from a mainstream app store.
- Credential or feed abuse follows when the app intercepts the camera stream at the operating-system level and substitutes synthetic video for the real feed.
- Impact occurs when the identity verification system accepts the manipulated stream as genuine and a fraudster passes remote proofing or onboarding checks.
Breaches seen in the wild
- Arup deepfake fraud 2024: Deepfakes of Arup's CFO and colleagues on a video call led a Hong Kong employee to transfer HK$200 million (about US$25.6m) to fraudsters.
- Meta AI Instagram Account Takeover: 20,225 Instagram accounts hijacked via compromised Meta AI support chatbot with overprivileged access.
Read and download The State of NHI & AI Agent Breach Report 2026, covering 200+ breaches impacting Non-Human Identities including AI Agents.
NHI Mgmt Group analysis
Camera provenance has become an identity control, not a device feature: Remote verification now depends on proving where the video feed originated, not just whether the device looks healthy. Native virtual camera attacks show that a legitimate permission grant can still produce fraudulent identity evidence, which means identity proofing and endpoint security now share the same trust boundary. Practitioners should treat capture provenance as part of the identity control stack.
Root status is an insufficient trust signal for modern fraud: The assumption that rooted or jailbroken devices are the main high-risk condition was designed for older attack paths. That assumption fails when the attacker stays inside standard permissions and preserves authentic-looking metadata while still substituting content. The implication is that posture checks alone cannot establish proofing integrity for remote onboarding.
Dynamic liveness is only effective when it is unpredictable to the attacker: Predictable challenge-response flows create a template that synthetic streams can imitate. The article’s description of active liveness weakness shows why verification design must move toward constantly varying, real-time validation and away from static prompts. Practitioners should evaluate whether their liveness model can be learned and reproduced at scale.
App store distribution changes the governance model for fraud tooling: When attack tooling appears in legitimate distribution channels, the organisation cannot rely on obvious malware signals or underground-only sourcing assumptions. That widens the exposure surface for consumer-facing verification journeys and shifts fraud prevention from perimeter suspicion to continuous intake governance. Teams should reassess trust in app distribution as part of onboarding risk.
Remote identity verification now needs joint ownership across fraud, IAM, and endpoint telemetry: This threat crosses traditional team boundaries because the failure is neither purely biometric nor purely cyber. The useful control model is one that joins proofing outcomes to device-integrity signals and real-time detection, so a single successful prompt does not outweigh a compromised capture path. Practitioners should align ownership before the next fraud wave forces the issue.
From our research library:
- Gartner predicts that by 2026, 30% of enterprises will consider identity verification solutions unreliable in isolation because of AI-driven attacks.
What this signals
Camera provenance is the new proofing boundary: The right question is no longer only whether a face matches a document, but whether the video evidence originated from the real camera path. Remote identity programmes that stop at liveness or posture will miss the attack class that lives between those controls.
Fraud prevention and endpoint security now share the same failure mode: Native virtual camera abuse is useful because it looks legitimate to both the operating system and the verifier. That means the control design has to join application-level proofing with device-level integrity and behavioural monitoring.
Attackers do not need exotic access to defeat weak proofing: When ordinary permissions are enough to inject synthetic video, the governance assumption that suspicious outcomes require suspicious permissions no longer holds. Identity teams should expect more abuse of standard app ecosystems, not less.
For practitioners
- Instrument the full camera pipeline Measure whether your verification flow can detect feed substitution anywhere between hardware capture and the application decision point, not only at login or onboarding.
- Replace predictable liveness prompts Review active liveness flows for reusable user movements that can be learned by synthetic media and move toward more variable, session-specific validation.
- Correlate device integrity with proofing outcomes Require the proofing engine to weigh device integrity, OS-level signals, and session context together instead of letting a single green check override the rest.
- Feed fraud telemetry into response workflows Route suspected native camera events into investigation and step-up decisions so repeated attempts are visible as a pattern rather than isolated failures.
Key takeaways
- Native virtual camera attacks are a remote identity verification failure because they manipulate the camera feed without needing rooted devices or obvious operating-system alerts.
- The article ties the threat to a 2,665% rise in 2024 and a peak of 785 weekly incidents in Q2 2024, which shows the tactic has moved into operational use.
- The practical answer is to verify capture provenance, vary liveness controls, and correlate proofing outcomes with device integrity and fraud telemetry.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 and MITRE ATT&CK address the attack and risk surface, while NIST CSF 2.0 sets the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Non-Human Identity Top 10 | NHI-04 — Insecure Authentication | The article centers on fraudulent verification streams defeating identity proofing. |
| NHI-06 — Insecure Cloud Deployment Configurations | The threat exploits weak trust boundaries in the capture and verification pipeline. | |
| NHI-10 — Human Use of NHI | Fraudsters use ordinary apps and device permissions to impersonate a human identity. | |
| Recommendation — Treat proofing flows as insecure if they trust camera output without provenance validation. Review verification architecture for trust assumptions that allow feed substitution inside standard permissions. Map identity proofing abuse paths where non-human tooling is used to defeat human verification. | ||
| NIST CSF 2.0 | PR.AA-05 — Access Permissions, Entitlements and Authorizations | The attack abuses legitimate permissions rather than obvious compromise. |
| Recommendation — Align verification decisions with entitlement review so legitimate permissions do not imply trusted evidence. | ||
| MITRE ATT&CK | TA0006;TA0040 — Credential Access; Impact | The attack chain targets identity acceptance and fraud impact rather than infrastructure compromise. |
| Recommendation — Map observed synthetic-media abuse to credential-access and impact tactics in fraud detections. | ||
Key terms
- Native Virtual Camera: A native virtual camera is a software tool that intercepts a device’s camera feed and replaces it with synthetic or replayed video. It usually operates within normal app permissions, which makes it difficult for standard endpoint controls to distinguish from legitimate camera use.
- Capture Provenance: Capture provenance is the ability to trace an identity record back to the exact person, device, place, and workflow that created it. It matters because a record without provenance may still exist in a system, but it cannot be confidently defended in audit, fraud review, or dispute resolution.
- Dynamic Liveness: A verification method that checks for active, changing human presence rather than a static image or recorded artefact. It is designed to resist replay, deepfake, and virtual-camera attacks by requiring real-time interaction and freshness across the verification step.
- Device Integrity Check: A control that evaluates whether a mobile device or runtime environment is behaving as expected before trust is granted to its signals. It helps distinguish a genuine onboarding attempt from emulator-based, rooted, or instrumented activity that may be trying to fake a legitimate user context.
Deepen your knowledge
NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
Published by the NHIMG editorial team on June 11, 2026.
Updated on October 10, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org