Injection attacks targeting iOS skyrocketed 1,151% YoY over the second half of 2025, fuelled by threat actors moving to “industrialise” AI‑driven deception aimed at businesses, according to new findings from iProov.
The identity security firm’s latest Annual Threat Intelligence Report shows a sudden spike in iOS‑focused injection attacks last year, with H1’25 seeing a modest 14% year-on-year rise before activity surged in the second half of the year, giving way to a 741% surge in injection attacks by year’s end.
iProov said that this flood of activity marks the industrialisation of an attack technique once feasible only for experimental or state-sponsored use, with attackers moving from isolated operations to weaponised, repeatable playbooks they can deploy at scale.
According to the report, in September, threat researchers saw hackers begin to use a “highly specialised” iOS video injection tool that allowed them to offload the heavy processing of AI-generated deepfakes to a remote machine, before injecting the finished product directly into the device’s video stream, bypassing the physical camera entirely.
iProov said that, while this tool is for now only usable on jailbroken devices, a Version 2.0 is quickly being developed for wider use, meaning that security plans built on the idea that iOS provides some inherent level of protection “need immediate review”.
Looking further, the report found that deepfakes are increasingly being used beyond identity verification systems to impact everyday corporate workflows, particularly across video-based interactions, with advanced image generators such as Nano Banana making it far easier to create highly realistic synthetic identities from minimal source material.
Where once attackers needed a physical device and technical know-how to spoof their way past biometric checks, iProov said that all they need now is access to a cloud emulator and virtual camera software to stream high-quality deepfakes directly into verification applications.
Recommended reading
- Is It Now Practically Impossible To Identify Deepfakes?
- UK Partners with Microsoft for Deepfake Detection Framework
- Too Authentic to be Synthetic: The Psychology Behind AI Voice Scams
The report warned that these tools have become sophisticated enough to produce deepfakes with minimal lag, making it easier for attackers to pass a live verification prompt, which iProov said has effectively made the old style of “liveness checks”, like repeating a phrase or nodding, obsolete.
Arguing that static approaches to identity verification are quickly being outpaced, iProov said that organisations must lean more on AI defence and adopt systems that continuously monitor environments and evolve with the threat landscape.
“Identity is becoming the new battleground in cybersecurity,” said Dr. Andrew Newell, chief scientific officer at iProov.
“Generative AI is allowing attackers to industrialise digital impersonation at scale. To defend against this, organisations must be able to establish genuine human presence in digital interactions to ensure trust and security.”





