BEGIN:VCALENDAR
VERSION:2.0
PRODID:Data::ICal 0.24
BEGIN:VEVENT
DESCRIPTION:   'Title: Your Bank Thinks I'm You: A Complete Kill Chain Agai
 nst Mobile\n   Banking Security\n   Tags: DEF CON Official Talk | Demo ðŸ’
 » | Tool ðŸ›  | Exploit ðŸª²\n   When: Friday\, Aug 7\, 15:30 - 16:30 PDT\
 n   Where: LVCCW Level 1 Hall 3 1007 (Main Track 2) and DCTV-2 - [1]Map\n\
 n   Description:\n   Mobile banking apps stack multiple security layers: R
 ASP (runtime\n   protection)\, root/jailbreak detection\, anti-instrumenta
 tion\, biometric\n   KYC with liveness detection\, and AI-powered anti-dee
 pfake. Each layer\n   promises to stop attackers. We defeated all of them 
 -- in production\n   apps used by millions.\n\n   We present a full kill c
 hain against mobile banks and digital wallet\n   apps from a Latin America
 n country\, demonstrating how an attacker with\n   an Android phone and op
 en-source tools can: (1) bypass RASP and root\n   detection using kernel-l
 evel root solutions and publicly available\n   modules\, achieving 100% ev
 asion of OS integrity and anti-hacking\n   controls\; (2) use Frida to dyn
 amically instrument biometric SDKs\,\n   injecting controlled frames into 
 the liveness capture flow by hooking\n   the "best result" getter and repl
 acing the YUV buffer\; (3) bypass KYC\n   identity verification by substit
 uting selfie images and crafting\n   coherent template+photo payloads that
  the backend accepts as\n   legitimate\; and (4) generate AI-synthetic fac
 es from photos that pass\n   liveness detection with 0% detection rate.\n\
 n   Every banking app we tested fell. The different RASPs and biometric\n 
   SDKs are deployed in 30+ countries\, protecting hundreds of millions of\
 n   users. We'll show why that should worry you. Video demos included.\n\n
      1. KernelSU Project - https://kernelsu.org\n\n     2. Kitsune Magisk 
 Fork -\n       https://github.com/1q23lyc45/KitsuneMagisk/tree/kitsune\n\n
      3. Frida Dynamic Instrumentation Toolkit - https://frida.re\n\n     4
 . JADX Decompiler - https://github.com/skylot/jadx\n\n     5. RootBeerSamp
 le Root Detection Tool -\n       https://github.com/nickcaballero/RootBeer
 Sample (reference\n       implementation)\n\n     6. TMLP Team / GooseBt S
 tudio - Root bypass module configurations\n       (GitHub\, publicly avail
 able)\n\n     7. ImNotADeveloper - Xposed module that hides developer mode
  and USB\n       debugging status from app detection -\n       https://git
 hub.com/auag0/ImNotADeveloper\n\n     8. Public KYC bypass repositories (r
 eferenced for threat landscape\n       awareness):\n\n         * https://g
 ithub.com/kycbypass/Android-Phone-Bypass-KYC-verification---No-root-requir
 ed\n\n         * https://github.com/hxreborn/biometric-bypass\n\n         
 * https://github.com/nocomp/deep-ofensive-ai\n\n   Speakers:Xavier "@xafer
 ima" Riofrio Machado\,Alex Tipan\n\n   SpeakerBio:  Xavier "@xaferima" Rio
 frio Machado\, Fintech Ecuador\n\n   Computer Science Engineer with an MSc
  in Cybersecurity\, specialized in\n   offensive security\, vulnerability 
 research\, and adversarial analysis\,\n   with a strong focus on mobile (A
 ndroid & iOS) security.\n\n   I identify systemic weaknesses through logic
 al reasoning\, abuse of\n   flawed assumptions\, and hands-on exploitation
  of complex workflows\n   across mobile\, web\, and API-driven environment
 s. My experience\n   combines deep technical rigor with practical red team
 ing\, allowing me\n   to model realistic attack paths instead of theoretic
 al risks.\n\n   I have worked in high-demand environments such as CERN and
  currently\n   contribute to securing fintech and digital wallet ecosystem
 s\, where\n   mobile platforms are critical attack surfaces. While offense
 -driven by\n   design\, I translate offensive findings into concrete defen
 sive\n   controls that actually withstand real-world attackers.\n\n   Spea
 kerBio:  Alex Tipan\, Fintech Ecuador\n\n   Cybersecurity professional spe
 cialized in application security\, with a\n   focus on offensive analysis 
 of mobile apps\, bypassing RASP controls\,\n   and assessing facial biomet
 ric workflows. Since school\, he has been\n   self-taught in programming\,
  hacking\, Linux\, networking\, and\n   cryptography\, later strengthening
  his academic foundation through a\n   degree in Computer Systems Engineer
 ing. He currently conducts hands-on\n   research on protection evasion in 
 financial applications\, including\n   advanced instrumentation techniques
  and validation of real-world risks\n   in authentication processes. His w
 ork aims to translate complex\n   technical findings into concrete defensi
 ve security improvements.\n\n   '\n\n   1. #LVCCW_Level1_Hall3\n\n\n
DTEND:20260807T233000Z
DTSTART:20260807T223000Z
LOCATION:DEF CON Talks - LVCCW Level 1 Hall 3 1007 (Main Track 2) and DCTV-
 2
SUMMARY:Your Bank Thinks I'm You: A Complete Kill Chain Against Mobile Bank
 ing Security
END:VEVENT
END:VCALENDAR
