Sign in
Resources

Beyond deepfakes
detecting real-time keystroke injection and llm-assist scripts during live video pre-interviews

Article • 25 Sep 2026 • 6 min read •

By early 2026, hiring fraud shifted from static resume fabrication to real-time AI assistance during live video screens. According to data from Fabric, AI-flagged interview cheating jumped from 9% of interviews in July 2025 to 38.5% by January 2026 across nearly 20,000 analyzed video interviews—hitting 48% in technical and software engineering roles.

The interview has quietly stopped being a test of who a person is or what they can do. We are no longer just screening candidates. We are matching wits against local real-time overlay copilots, audio-feed injection software, and keystroke-injection scripts that make an underqualified or proxy applicant sound like a Principal engineer in real time.

The Economics of Asymmetric Deception

91%
Recruiters and hiring managers who have spotted or suspected candidate deception during the hiring process
Greenhouse, 2026

To understand why live interview fraud has proliferated so aggressively, we have to look at the economic incentives through an anthropological lens. Hiring is a high-stakes information asymmetry game. The employer is trying to de-risk a five-figure or six-figure capital allocation (a salary) based on a few hours of conversation, while the applicant is improving for maximum payout with minimal marginal effort.

Generative AI has radically collapsed the marginal cost of faking competence. A syndicate or an individual applicant can deploy a localized LLM copilot that listens to the audio stream of a Zoom or Teams call, transcribes the interviewer's question, generates an optimal, jargon-dense architectural response, and feeds it directly into a translucent overlay on the candidate's monitor within 400 milliseconds.

The traditional interview format—relying on a recruiter's gut feel and a hiring manager's casual conversational cadence—is fundamentally unequipped for this reality. In fact, a 2026 survey by Greenhouse found that 91% of recruiters and hiring managers have spotted or suspected candidate deception during the hiring process. Meanwhile, 62% of hiring professionals admit that job seekers are currently better at faking credentials and using AI than HR teams are at catching them (The Hire Hub, 2026).

When the tools of deception outpace the tools of verification, organizations suffer from adverse selection. You do not end up with the candidate who possesses deep domain expertise; you end up with the candidate who possesses the most sophisticated local execution stack.

Beyond the Static Deepfake: The Mechanics of Real-Time Injection

Three Primary Techniques of Modern Operational Fraud
1
Audio-Feed Loopers and Speech-to-Text Copilots
System audio routes interviewer questions into a customized LLM fine-tuned on technical or behavioral rubrics.
2
Keystroke Injection and Script Overlays
Macro-driven scripts populate IDEs at superhuman speeds during live coding sessions, bypassing genuine problem-solving.
3
Proxy Switching and Dual-Operator Setups
A knowledgeable proxy operator handles technical screenings via background audio while a clean-faced applicant parrots instructions.

Most enterprise security discussions around hiring fraud still focus on visual anomalies—blurry earlobes, mismatched lighting, or jittery lip-syncing associated with deepfake video generation. But sophisticated actors have largely abandoned standalone deepfake video streams because they are resource-intensive and prone to stuttering under bandwidth fluctuations.

Instead, modern operational fraud relies on three primary techniques that run silently on the candidate's local machine:

  1. Audio-Feed Loopers and Speech-to-Text Copilots: The candidate joins the call with a clean, legitimate video feed of themselves, but their system audio is routed through a virtual audio cable that feeds the interviewer's questions directly into a customized LLM fine-tuned on technical documentation or behavioral rubrics.
  2. Keystroke Injection and Script Overlays: During live coding or technical design sessions, candidates use macro-driven scripts or injected keystrokes that populate IDEs at superhuman speeds, bypassing the halting, iterative thought process characteristic of genuine problem-solving.
  3. Proxy Switching and Dual-Operator Setups: A knowledgeable proxy operator handles the technical screening phase via background audio or text prompts, while a clean-faced applicant sits in front of the camera, simply parroting instructions with a slight audio delay.

These methods exploit the blind spots of standard video conferencing software. Zoom and Microsoft Teams are designed for communication fidelity, not forensic authentication. They do not care if the words coming out of a candidate's mouth were generated by an on-device local weights model three-tenths of a second prior.

The Continuity Problem in Talent Pipelines

Screening and interview fraud is fundamentally a continuity problem. If you let identity, voice, behavioral cadence, and syntax profiles change between pipeline stages without noticing, you end up hiring the best proxy tool rather than the best human.

Consider how a typical enterprise pipeline flows: A candidate submits a resume (often optimized by an LLM), passes an asynchronous video assessment, completes a recruiter phone screen, and then enters a technical panel. At each stage, the data is siloed. The recruiter looking at the live video call rarely cross-references the linguistic patterns of the initial application text, let alone the typing telemetry captured during an online code assessment.

When companies rely on fragmented point solutions—an ATS here, a scheduling tool there, a basic video recorder somewhere else—they create seams that bad actors easily slip through. According to Humanly TA Insights, maintaining strict verification across every touchpoint of the candidate journey is the only way to preserve pipeline integrity. If the syntax profile of a candidate's written responses drastically diverges from their spoken cadence, or if their response latency violates human cognitive processing limits, the system should trigger an immediate audit.

Redesigning the Assessment Architecture

The instinct of many HR leaders when faced with a 38% cheating rate is to lock down the candidate's environment. We see a rush toward draconian proctoring tools: browser lockdowns that disable secondary monitors, eye-tracking extensions that penalize candidates for looking away from the camera, and aggressive keystroke loggers that raise privacy concerns and alienate top-tier passive talent.

This is a category error. Fighting AI-assisted fraud with pure surveillance is an arms race you will eventually lose. The moment you lock down a browser, bad actors route their copilots to a secondary device, a smart glasses display, or a localized hardware capture card.

Instead, talent acquisition teams must pivot toward two complementary strategies: behavioral telemetry and assessment redesign.

First, embrace passive behavioral analytics that evaluate response latency, linguistic drift, and interaction metadata without violating candidate privacy laws or degrading the employer brand. Real-time AI copilots introduce a distinct micro-delay—a fraction of a second where the candidate's eyes track text rather than engage in spontaneous eye contact, coupled with a rhythmic, highly structured sentence syntax uncharacteristic of off-the-cuff human speech.

Second, stop running technical screens as if it were 2019. If an engineer can pass your coding interview purely by running an AI copilot, your interview questions are measuring the wrong thing. Modern technical assessment should embrace AI-assisted workflows. Instead of banning copilots, evaluate how candidates direct them. Ask them to debug flawed AI-generated code, critique an LLM's architectural proposal, or explain the trade-offs of a system design in a live, interactive whiteboard setting where real-time pivoting destroys scripted responses.

The Operational Reality for Hiring Teams

As organizations grapple with the reality that nearly half of technical screening interviews face AI interference, talent leaders must establish clear boundaries between legitimate candidate preparation (using AI to practice or format resumes) and active operational fraud (using real-time copilots to fake core competencies during live evaluations).

This requires shifting from a posture of blind trust to one of verified resilience. It means integrating cross-stage consistency checks into your ATS and interview intelligence workflows, ensuring that the person who boards your onboarding call on day one is mathematically and behaviorally identical to the person who cleared the initial screen.

The interview was never broken because people started using AI. It broke because we refused to acknowledge that the evaluation model of the pre-generative era could survive in a world where intelligence has near-zero marginal cost. Catching keystroke injection and live script assistance isn't about building a better warden; it's about building an assessment framework that demands genuine human reasoning where automation cannot follow.