What is click injection?
Click injection is an Android attribution fraud where a malicious app on the phone detects that another app is being installed and fires a fake ad click in the last seconds before the install finishes. The fraudster then appears to be the last click and collects the advertiser's install payout for a user who arrived organically or through another channel.
Click injection exploits last-click attribution: whoever registered the most recent click before an install gets paid. The fraudulent app, often a flashlight, cleaner or similar utility, listens for install broadcasts and triggers a click through an ad network. Because the install is real, simple bot filters miss it.
The giveaway is time: a click registered seconds before the app opened is implausible because downloads take time. MMPs compare click time, install-begin time from the app store and first-open time to reject injected clicks. It is a cousin of click spamming; both are forms of attribution fraud that steal credit rather than fake users.