Game Over: How AI Is Defeating Biometric Security
- By Winston Thomas
- June 15, 2025

The AI-driven malware war is already here. And, it’s no surprise we’re losing.
While the cybersecurity community debates the implications of AI-powered threats, criminal organizations have quietly integrated artificial intelligence into their mobile malware. This upgrade has transformed mobile malware from a nuisance into an existential threat to digital commerce.
Mobile is fast becoming the preferred battlefield. Why would threat actors attack a network ringed with intrusion detection, honeypots, and AI-driven sentinels? The smartphone offers an asymmetric war — a criminal enterprise that constantly probes and learns against an individual balancing convenience, privacy, and security, where a single moment of weakness is all it takes.
So it’s no surprise that in Singapore alone, malware-enabled scams siphoned SGD129.1 million from victims in 2024 according to the Singapore Police Force (SPF)’s latest Annual Scams and Cybercrime Brief 2024 (PDF download). This represents 11.6% of the country’s staggering SGD1.1 billion in total cybercrime losses.
But these numbers only tell part of the story. Behind each stolen dollar lies a fundamental shift in how cybercriminals operate. They have gone AI-native, while defenders remain trapped in yesterday’s security paradigms. According to Jan Sysmans, a mobile app security evangelist at Appdome, it’s time to rewire our approach to mobile malware.
AI targets security fundamentals
“The bad guys are way, way ahead,” Sysmans notes. “They’re innovating at lightning speed because criminal organizations are already fully AI-native.”
This speed advantage manifests in multiple ways. AI-powered malware can now:
- Generate convincing phishing messages tailored to individual victims using scraped social media data.
- Create fake mobile apps that pass cursory security reviews.
- Develop polymorphic code that evades signature-based detection.
- Launch coordinated, multi-vector attacks simultaneously.
- Learn from failed attempts and adapt in real-time.
Meanwhile, traditional security solutions remain reactive, dependent on known threat signatures that AI-driven attacks easily circumvent.
The most chilling development, however, is not another banking trojan but a simple, scalable way to create deepfake authentication bypasses. These attacks are systematically dismantling the biometric security infrastructure that companies have spent years building and trusting.
“Fraudulent organizations have found ways to either turn off, bypass, or just change the outcome for all of the Face ID, liveness checks, and biometric authentication solutions that we use and trust on a daily basis,” explains Sysmans.
He recalls how one major Latin American bank discovered this nightmare firsthand when its liveness check SDK came under sustained attack, bleeding $10,000 per hour. When the bank approached its SDK vendor, the response was devastating: “We don't know how to fix it because they are fundamentally attacking the underlying architecture of our solution.”
This isn’t an isolated incident. Sysmans warns it's contributing to a systemic collapse, as the biometric systems that financial institutions and government agencies rely on are being compromised by AI that can generate convincing deepfake videos in real-time.
Compliance-driven security creates a false sense of protection
The disconnect between perceived security and actual protection has never been greater. Organizations continue to pass penetration tests and meet compliance requirements while remaining completely vulnerable.
“You pass the [penetration] test, you meet your objectives, you adhere to industry regulations, and you think you’re fine,” Sysmans explains. “But attackers are using tools and methods that bypass all the standard protections.”
This creates a catastrophic blind spot. The tools used in standard security testing — jailbreak detection, root detection, anti-tampering measures — are irrelevant against AI that can dynamically adapt to the specific defenses it encounters. Security teams celebrate compliance victories while attackers exploit techniques that traditional frameworks never anticipated.
The threat extends far beyond financial services. Sysmans describes a loyalty program attack where criminals used AI to systematically steal reward redemptions and resell them on secondary markets. This attack highlights a broader danger: AI doesn't just make existing attacks more effective; it enables entirely new categories of fraud that slip through the gaps in compliance.
“If you can do that on one app, what is that criminal organization going to do?” Sysmans warns. “It’s going to take these learnings and go to all other apps.” The cross-pollination of attack techniques means a vulnerability in one application becomes a systemic weakness across an entire industry.
Agentic AI adds a new layer of complexity
And it’s about to get worse. The current wave of AI-driven malware is only the beginning. The emergence of agentic AI systems capable of autonomous decision-making and proactive task execution will fundamentally reshape the threat landscape within months, not years.
“AI agents are going to completely change everything we do,” Sysmans predicts. “We’re going to see a ‘Crossing the Chasm’ event happening in the second half of this year.”
When AI agents can autonomously manage calendars, financial transactions, and communications, the attack surface expands exponentially. Compromising an AI agent won't just provide access to a user’s data; it will grant ongoing control over their future decisions and actions.
The doomsday clock for mobile security ticks
We stand at the precipice of a security crisis. Criminal organizations have weaponized one of the most powerful technologies in human history while defenders cling to outdated paradigms and the false comfort of compliance.
The mobile devices in our pockets have become our digital identities—gateways to our financial and personal lives. Now, they are compromised territories in a war most people don’t even know is being fought. AI-driven malware isn’t coming; it’s here, it’s learning, and it’s winning.
As Sysmans argues, traditional security approaches aren't just inadequate; they are actively dangerous, providing an illusion of protection while the real threats operate undetected. The organizations that survive the coming security apocalypse will be those that abandon legacy thinking and embrace AI-native defense strategies.
Appdome itself is helping companies prepare while preparing itself for AI-driven malware. It is strengthening its Account Takeover Protection suite with 32 new AI-Native dynamic defense plugins that provide Mobile Account Protection to the new frontline of Account Takeovers (ATOs) and On-Device Fraud (ODF). The new plugins are designed to help mobile brands and businesses maintain trust in the mobile experience and combat increasingly sophisticated malware that targets user identity, account creation, and transactions in mCommerce and other applications.
The company is also hardening the GenAI models used for threat synthesis. “Our AI models are trained exclusively on proprietary, curated datasets — not public or user-contributed data — which eliminates the risk of attackers poisoning the training pipeline,” explained Sysman. “Crucially, the AI does not expose inference data or behavior patterns that attackers could use to craft adversarial inputs. Instead, all threat decisions are translated into automated protections, giving attackers no feedback loop to exploit.”
“We also use GenAI to generate synthetic threats and red-team our defenses continuously, helping us stay ahead of evolving attack techniques. This closed, zero-trust approach ensures that Appdome’s AI can’t be hijacked or turned against us — or our customers,” adds Sysman.
For companies still debating how to counter AI-driven mobile malware, the clock is ticking. The attackers have a head start. The time to rethink mobile app security isn’t coming. It’s now.
Image credit: iStockphoto/Mininyx Doodle
Winston Thomas
Winston Thomas is the editor-in-chief of CDOTrends. He likes to piece together the weird and wondering tech puzzle for readers and identify groundbreaking business models led by tech while waiting for the singularity.