Download the PDF version
Artificial intelligence

The criminals’ AI is already in production. Banking’s isn’t.

Published:
7/8/2026

Somewhere in the debate over whether AI is ready for regulated banking, one side stopped debating and shipped. The criminals’ AI is in production — not in a lab, not on a roadmap, but at scale, iterating faster than any analyst queue can absorb. Cleafy Labs has the evidence.

Recent Cleafy Labs research, NFC Relay Goes Local: How AI Is Accelerating a New Wave of Independent Malware Developers, documents attackers using AI-assisted development to build advanced NFC relay attacks faster than ever before. This is not a future threat. It is the operating reality of criminal networks today.

SharkBot to Albiriox: the through-line is automation

You can read the trajectory in Cleafy Labs’ own casework. SharkBot (2021) automated the transfer itself, using an Automatic Transfer System to move money with minimal user input. PixPirate (2023) carried that automation onto instant-payment rails, running ATS fraud over Brazil’s Pix. Albiriox (2025) went further, handing attackers full remote control of the victim’s device for on-device fraud. Different techniques, one direction of travel: less human effort per fraud, more of the work automated.

Theft without a visible device

The newest wave targets the payment itself. That same Cleafy Labs research identifies two NFC-relay families — DevilNFC and NFCMultiPay — built independently by unrelated actors with no shared code, both carrying AI-assisted development fingerprints. When unconnected criminals converge on the same technique within months of each other, it has stopped being a trend and become a standard.

Both bundle social engineering — kiosk mode, branded fake interfaces — to keep the victim engaged while the relay completes and the card PIN is harvested. Add corroborating data on biometric injection attacks, such as those tracked by Group-IB, and the conclusion is unavoidable: banks now face adversaries capable of executing complex financial theft without ever producing a visible device. It is part of the same broader shift Cleafy Labs keeps tracking, from the Mirax Android RAT to AI-driven social engineering.

Every bank control is now a data point

Financial institutions are no longer fighting individuals. They face industrial-scale fraud factories running at a relentless pace. Criminals have probed bank controls for years — Cleafy Labs has documented device-fingerprint cycling and behavioural-biometric manipulation long before this wave of automation. What changed is the tempo. What once emerged over quarters now iterates in days, hours and minutes.

These systems treat every bank control as a data point to learn from, recalibrating to slip past defences in real time. Against that, a bank whose primary defence is a human analyst working through a queue isn’t merely slower. It is operating in a different temporal reality from the attack it is trying to intercept.

What machine-speed fraud demands next

The gap that matters isn’t one of intent, insight or even capability — banks understand this threat precisely. It is a gap in the operating model: machine-speed attacks met by human-speed defence. Closing it means letting a system observe, decide and act at the speed of the attack, with humans governing rather than queuing. That model is Autonomous Fraud Operations, and it stopped being theoretical in December 2025, when Cleafy put it into production.

The useful move, while the threat picture is fresh: ask the Head of Fraud one question — when an attack starts inside a customer session, how many people stand between the first signal and the response, and how long does it take. The attackers already know their answer. It is measured in seconds.

FAQs

What is AI-assisted malware development?

It is the use of AI tools to speed up the creation and variation of malware — generating new droppers, sending domains, device profiles and attack variants at a pace manual defences cannot match, turning fraud into an industrial, continuously iterating process.

What is an NFC relay attack?

An NFC relay attack captures and relays a victim’s contactless payment credentials to complete fraudulent transactions remotely. Cleafy Labs documents independent actors building these attacks with AI assistance, making the technique a de facto standard.

Why can’t human fraud teams keep pace with machine-speed fraud?

Automated attacks iterate in minutes and treat every control as a data point to learn from. A queue-based model where analysts review alerts manually operates on a slower timescale than the attack, so the campaign moves on before a human confirms the pattern.

Read more articles

Regulation

Banking fraud regulation: who now owns fraud inside a bank

Read more

Artificial intelligence

The ECB has set a deadline for machine-speed defence. Fraud got there first.

Read more

Prevention and detection

The fraud operational cost crisis: why the current model can’t scale

Read more